Crash Report For ManageACL_32.exe Created by using WinCrashReport http://www.nirsoft.net/utils/application_crash_report.html General Exception Information: Operating System: Microsoft Windows XP Service Pack 3, v.6419 (5.1.2600) Report Time: 25.Sep.2016 13:01:53 Process Filename: C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe Process ID: 3152 Thread ID: 3108 Process Description: Tweaking.com - ManageACL Process Version: 1.3.0.0 Process Company: Tweaking.com Product Name: Tweaking.com - ManageACL Product Version: 1.3.0.0 Crash Address: 00414F50 Crash Address (Relative): ManageACL_32.exe+0x14f50 Exception Code: C000001D Exception Description: {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction. Crash Code Bytes: 66 0F D6 00 8B 44 24 0C 83 C0 04 50 E8 0E 41 01 00 83 C4 08 8B C6 5E C2 04 00 CC CC CC CC CC CC F0 FF 41 04 C3 CC CC CC CC CC CC CC CC CC CC CC 55 8B EC 6A FF 68 78 F4 45 00 64 A1 00 00 00 00 Strings in the stack: 0013B814 00140000 -> Actx 0013B838 001410C8 -> SsHd, 0013B884 00261FC0 -> ` & 0013BA30 7FFDFC00 -> advapi32.dll 0013BAAC 0013BCB4 -> WS\system32\dwwin.exe 0013BBA4 0017B120 -> C:\WINDOWS\system32\dwwin.exe 0013BC24 0017ABE8 -> C:\WINDOWS\system32 0013BCD0 00690077 -> trackbar32 0013BCD4 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013BE54 0013BF44 -> dwwin.exe 0013C1D8 0017AC10 -> dwwin.exe 0013C4C8 0013C500 -> dwwin.exe 0013C558 0013C5F8 -> 5-21-1409082233-920026266-1708537768-1003 0013C5C8 001632BE -> S-1-5-21-1409082233-920026266-1708537768-1003 0013C5E8 0013C5F0 -> S-1-5-21-1409082233-920026266-1708537768-1003 0013C628 002D0036 -> ȜȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013C64C 7C97EF02 -> stem32\dwwin.exe 0013C654 7C97EEE8 -> advapi32.dll 0013C6A8 77E03C3C -> %HKEY_LOCAL_MACHINE 0013C6AC 0016D898 -> C:\WINDOWS\*.exe 0013C740 0013CB80 -> ternet Files\OLK* 0013C760 0013C974 -> Intern즜写粑진ä 0013C8E0 0013D0FC -> win.exe 0013C92C 001766D8 -> *.exe 0013C944 0013C950 -> C:\WINDOWS\*.exe 0013C974 006E0049 -> istBox 0013C97C 006E0072 -> SOFTWARE\Classes\Unmarshalers",4,"O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522 0013CA10 0013CA80 -> @"& 0013CA24 0013CA70 -> P"& 0013CAD8 0013CDB8 -> P"& 0013CB1C 7C915076 -> \REGISTRY\USER\ 0013CB40 0013CB5C -> \WINDOWS\*.exe 0013CBB4 77DDB648 -> \CodeIdentifiers 0013CC08 0013CC0C -> \REGISTRY\USER\S-1-5-21-1409082233-920026266-1708537768-10체 0013CC78 002D0038 -> ȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013CD48 0013D0D0 -> C:\WINDOWS\system32\dwwin.exe 0013CF80 69451B5C -> Winsta0\Default 0013D05C 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013D0BC 0013D0F8 -> dwwin.exe 0013D504 0013E318 -> C:\WINDOWS\system32 0013D510 0013DE02 -> -x -s 1852 0013D6C0 0017A9DE -> system32 0013D890 7C881934 -> ntdll.dll 0013D91C 0013DC30 -> X+& 0013D948 77B402A5 -> NTDLL.DLL 0013DAA8 0013E520 -> P:\Temp\_shared\b5ba_appcompat.txt 0013DC64 00262ED8 -> x/& 0013DE08 002D0020 -> ʼnŋŐŕƊƌƚǨȇȌȓȜȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013DE40 7F6F2190 -> C:\WINDOWS\system32 0013DE60 0013F614 -> ManageACL_32.exe 0013DEBC 0013F490 -> watson.microsoft.com 0013DEE0 0013DF08 -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013DFF4 69451A84 -> d3d9.dll 0013E054 0016F2E8 -> Unrestricted 0013E0E8 0016FD80 -> stem32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0 0013E3C8 0016D916 -> n\SystemRoot%*.exe 0013E4A0 0013F59A -> Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013E4BC 0013F594 -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013E4D4 0013E50C -> files 0013E520 003A0050 -> is program cannot be run in DOS mode.$ 0013E780 0013EA72 -> watson.microsoft.com 0013E7A4 00169B00 -> ncalrpc 0013E7A8 00169B18 -> IcaApi 0013E7CC 00374228 -> Software\Policies\Microsoft\Windows\System 0013EA90 002E0074 -> u‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013F290 0013F2E0 -> DOWS\system32\faultrep.dll 0013F2C8 0013F2D4 -> C:\WINDOWS\system32\faultrep.dll 0013F334 0013F480 -> faultrep慷獴湯洮捩潲潳瑦挮浯 0013F35C 0013F910 -> C:\WINDOWS\system32\faultrep.dll 0013F3B4 00470046 -> lid list format entry 0013F3E0 0013F458 -> C:\WINDOWS\system32\faultrep慷獴湯洮捩潲潳瑦挮浯 0013F66C 0013F73A -> ReportFault 0013F6D8 0013F734 -> ~}Ei 0013F714 0013F874 -> ~}Ei@ 0013F824 7FFE0030 -> C:\WINDOWS 0013F83C 00169508 -> %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe 0013F854 0013F922 -> S\system32\faultrep.dll 0013F884 0013F920 -> WS\system32\faultrep.dll 0013F890 7C81A984 -> Debugger 0013F8F4 0016D034 -> drwtsn32 -p %ld -e %ld -g 0013F960 004647AC -> FlsGetValue 0013FAF8 00461CB4 -> kernel32.dll 0013FC04 0013FF3C -> `FF 0013FD28 0013F2FC -> faultrep.dll 0013FD4C 0013F44C -> ’“”•–—C:\WINDOWS\system32\faultrep慷獴湯洮捩潲潳瑦挮浯 0013FD94 00150000 -> Actx 0013FDA4 0013F472 -> stem32\faultrep慷獴湯洮捩潲潳瑦挮浯 0013FE20 00163C00 -> NDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0 0013FF40 00464668 -> bad allocation Call Stack (Method 1): 0013FE40 0045C984 ManageACL_32.exe+0x5c984 0013FE6C 0045C703 ManageACL_32.exe+0x5c703 0013FEA0 0045CA82 ManageACL_32.exe+0x5ca82 0013FF14 0045CD00 ManageACL_32.exe+0x5cd00 0013FF58 00401551 ManageACL_32.exe+0x1551 0013FF7C 0042391C ManageACL_32.exe+0x2391c 0013FFC0 7C81776F kernel32.dll!RegisterWaitForInputIdle+0x49 0013FFF0 00000000 Call Stack (Method 2): 0013FB54 00414F50 ManageACL_32.exe+0x14f50 0013FC5C 7C90D80A ntdll.dll!NtQueryInformationProcess+0xc 0013FCEC 7C9115F9 ntdll.dll!RtlLogStackBackTrace+0x25 0013FCF8 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013FD04 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013FD0C 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013FD3C 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013FD40 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013FD54 7C9142B9 ntdll.dll!RtlDosPathNameToNtPathName_U+0x94 0013FD64 7C926620 ntdll.dll!RtlDosSearchPath_Ustr+0x1ed 0013FDB8 7C97E140 ntdll.dll!NlsMbOemCodePageTag+0x98 0013FDC0 7C90E920 ntdll.dll!strchr+0x113 0013FDC4 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013FDD0 7C911452 ntdll.dll!RtlDeleteCriticalSection+0xd8 0013FDD4 7C911483 ntdll.dll!RtlDeleteCriticalSection+0x109 0013FDD8 7C97E120 ntdll.dll!NlsMbOemCodePageTag+0x78 0013FDDC 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013FE00 7C911468 ntdll.dll!RtlDeleteCriticalSection+0xee 0013FE10 7C9113F2 ntdll.dll!RtlDeleteCriticalSection+0x78 0013FE30 00425EBF ManageACL_32.exe+0x25ebf 0013FE38 004784D0 ManageACL_32.exe+0x784d0 0013FE44 0045C984 ManageACL_32.exe+0x5c984 0013FE64 00460CF8 ManageACL_32.exe+0x60cf8 0013FE70 0045C703 ManageACL_32.exe+0x5c703 0013FE90 0045CF18 ManageACL_32.exe+0x5cf18 0013FE98 00434752 ManageACL_32.exe+0x34752 0013FEA4 0045CA82 ManageACL_32.exe+0x5ca82 0013FEB8 004615D0 ManageACL_32.exe+0x615d0 0013FEDC 004784B4 ManageACL_32.exe+0x784b4 0013FEE4 7C9115C6 ntdll.dll!RtlInitializeCriticalSectionAndSpinCount+0xac 0013FF0C 00460D36 ManageACL_32.exe+0x60d36 0013FF18 0045CD00 ManageACL_32.exe+0x5cd00 0013FF1C 004835A4 ManageACL_32.exe+0x835a4 0013FF3C 00464660 ManageACL_32.exe+0x64660 0013FF50 00460D81 ManageACL_32.exe+0x60d81 0013FF5C 00401551 ManageACL_32.exe+0x1551 0013FF64 00434CF9 ManageACL_32.exe+0x34cf9 0013FF74 00401547 ManageACL_32.exe+0x1547 0013FF80 0042391C ManageACL_32.exe+0x2391c 0013FF84 00461538 ManageACL_32.exe+0x61538 0013FF88 004615D8 ManageACL_32.exe+0x615d8 0013FFB4 00429BF0 ManageACL_32.exe+0x29bf0 0013FFC4 7C81776F kernel32.dll!RegisterWaitForInputIdle+0x49 0013FFE4 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013FFE8 7C817778 kernel32.dll!RegisterWaitForInputIdle+0x52 0013FFF8 00423A1D ManageACL_32.exe+0x23a1d Processor Registers: EAX 00169A24 -> 50 03 16 00 5C 00 54 00 65 00 6D 00 05 00 03 00 EBX 0013FEC0 ECX 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 EDX 0013FF3C -> `FF ESI 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 EDI 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 EBP 0013FE40 ESP 0013FE28 EIP 00414F50 ManageACL_32.exe+0x14f50 GS 00000000 FS 0000003B ES 00000023 DS 00000023 CS 0000001B SS 00000023 EFlags 00010286 Modules List: ManageACL_32.exe ; 00400000 - 00491000 ; 00091000 ; Tweaking.com - ManageACL ; 1.3.0.0 ; 1.3.0.0 ; Tweaking.com - ManageACL ; Tweaking.com ; 572 824 ; 14.Jul.2016 10:50:23 ; C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe ; ntdll.dll ; 7C900000 - 7C9B2000 ; 000B2000 ; Microsoft® Windows® Operating System ; 5.1.2600.6055 ; 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647) ; NT Layer DLL ; Microsoft Corporation ; 718 336 ; 09.Dec.2010 18:15:09 ; C:\WINDOWS\system32\ntdll.dll ; kernel32.dll ; 7C800000 - 7C8F6000 ; 000F6000 ; Microsoft® Windows® Operating System ; 5.1.2600.6293 ; 5.1.2600.6293 (xpsp_sp3_gdr.121001-1622) ; Windows NT BASE API Client DLL ; Microsoft Corporation ; 990 208 ; 03.Oct.2012 07:58:13 ; C:\WINDOWS\system32\kernel32.dll ; USER32.dll ; 7E410000 - 7E4A1000 ; 00091000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1425) ; Windows XP USER API Client DLL ; Microsoft Corporation ; 578 560 ; 01.Dec.2007 01:26:08 ; C:\WINDOWS\system32\USER32.dll ; GDI32.dll ; 77F10000 - 77F59000 ; 00049000 ; Microsoft® Windows® Operating System ; 5.1.2600.6460 ; 5.1.2600.6460 (xpsp_sp3_qfe.131009-0419) ; GDI Client DLL ; Microsoft Corporation ; 287 744 ; 09.Oct.2013 16:12:48 ; C:\WINDOWS\system32\GDI32.dll ; WINSPOOL.DRV ; 73000000 - 73026000 ; 00026000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-0108) ; Windows Spooler Driver ; Microsoft Corporation ; 146 432 ; 01.Dec.2007 01:27:06 ; C:\WINDOWS\system32\WINSPOOL.DRV ; ADVAPI32.dll ; 77DD0000 - 77E6B000 ; 0009B000 ; Microsoft® Windows® Operating System ; 5.1.2600.6382 ; 5.1.2600.6382 (xpsp_sp3_qfe.130422-0417) ; Advanced Windows 32 Base API ; Microsoft Corporation ; 618 496 ; 22.Apr.2013 12:37:18 ; C:\WINDOWS\system32\ADVAPI32.dll ; RPCRT4.dll ; 77E70000 - 77F03000 ; 00093000 ; Microsoft® Windows® Operating System ; 5.1.2600.6477 ; 5.1.2600.6477 (xpsp_sp3_qfe.131106-0418) ; Remote Procedure Call Runtime ; Microsoft Corporation ; 591 360 ; 07.Nov.2013 08:38:51 ; C:\WINDOWS\system32\RPCRT4.dll ; Secur32.dll ; 77FE0000 - 77FF1000 ; 00011000 ; Microsoft® Windows® Operating System ; 5.1.2600.5834 ; 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305) ; Security Support Provider Interface ; Microsoft Corporation ; 56 832 ; 25.Jun.2009 11:25:26 ; C:\WINDOWS\system32\Secur32.dll ; msvcrt.dll ; 77C10000 - 77C68000 ; 00058000 ; Microsoft® Windows® Operating System ; 7.0.2600.3264 ; 7.0.2600.3264 (xpsp.071130-1427) ; Windows NT CRT DLL ; Microsoft Corporation ; 343 040 ; 01.Dec.2007 01:25:48 ; C:\WINDOWS\system32\msvcrt.dll ; SHLWAPI.dll ; 77F60000 - 77FD6000 ; 00076000 ; Microsoft® Windows® Operating System ; 6.00.2900.5912 ; 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454) ; Shell Light-weight Utility Library ; Microsoft Corporation ; 474 112 ; 08.Dec.2009 12:23:28 ; C:\WINDOWS\system32\SHLWAPI.dll ; ole32.dll ; 774E0000 - 7761E000 ; 0013E000 ; Microsoft® Windows® Operating System ; 5.1.2600.6435 ; 5.1.2600.6435 (xpsp_sp3_qfe.130803-0418) ; Microsoft OLE for Windows ; Microsoft Corporation ; 1 289 728 ; 05.Aug.2013 16:30:32 ; C:\WINDOWS\system32\ole32.dll ; OLEAUT32.dll ; 77120000 - 771AB000 ; 0008B000 ; ; 5.1.2600.6341 ; 5.1.2600.6341 ; ; Microsoft Corporation ; 552 448 ; 26.Jan.2013 06:55:44 ; C:\WINDOWS\system32\OLEAUT32.dll ; OLEACC.dll ; 61880000 - 618BA000 ; 0003A000 ; Microsoft® Windows® Operating System ; 5.1.2600.6153 ; 7.0.2600.6153 (xpsp_sp3_gdr(oobla).110926-1140) ; Active Accessibility Core Component ; Microsoft Corporation ; 220 160 ; 26.Sep.2011 12:41:20 ; C:\WINDOWS\system32\OLEACC.dll ; IMM32.DLL ; 76390000 - 763AD000 ; 0001D000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1425) ; Windows XP IMM32 API Client DLL ; Microsoft Corporation ; 110 080 ; 01.Dec.2007 01:25:40 ; C:\WINDOWS\system32\IMM32.DLL ; LPK.DLL ; 629C0000 - 629C9000 ; 00009000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1425) ; Language Pack ; Microsoft Corporation ; 22 016 ; 01.Dec.2007 01:25:42 ; C:\WINDOWS\system32\LPK.DLL ; USP10.dll ; 74D90000 - 74DFB000 ; 0006B000 ; Microsoft(R) Uniscribe Unicode script processor ; 1.0420.2600.6421 ; 1.0420.2600.6421 (xpsp_sp3_qfe.130709-0421) ; Uniscribe Unicode script processor ; Microsoft Corporation ; 406 016 ; 10.Jul.2013 13:37:53 ; C:\WINDOWS\system32\USP10.dll ; api-ms-win-core-synch-l1-2-0.dll ; 10000000 - 10003000 ; 00003000 ; Microsoft® Windows® Operating System ; 10.0.10563.0 ; 10.0.10563.0 (th2_release.151003-2255) ; ApiSet Stub DLL ; Microsoft Corporation ; 19 864 ; 05.Nov.2015 22:54:46 ; C:\WINDOWS\system32\api-ms-win-core-synch-l1-2-0.dll ; faultrep.dll ; 69450000 - 69466000 ; 00016000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1425) ; Windows Error Reporting ; Microsoft Corporation ; 80 384 ; 01.Dec.2007 01:25:36 ; C:\WINDOWS\system32\faultrep.dll ; VERSION.dll ; 77C00000 - 77C08000 ; 00008000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1425) ; Version Checking and File Installation Libraries ; Microsoft Corporation ; 18 944 ; 01.Dec.2007 01:26:08 ; C:\WINDOWS\system32\VERSION.dll ; USERENV.dll ; 769C0000 - 76A74000 ; 000B4000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1433) ; Userenv ; Microsoft Corporation ; 727 040 ; 01.Dec.2007 01:26:08 ; C:\WINDOWS\system32\USERENV.dll ; WINSTA.dll ; 76360000 - 76370000 ; 00010000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1427) ; Winstation Library ; Microsoft Corporation ; 53 760 ; 01.Dec.2007 01:26:08 ; C:\WINDOWS\system32\WINSTA.dll ; NETAPI32.dll ; 5B860000 - 5B8B5000 ; 00055000 ; Microsoft® Windows® Operating System ; 5.1.2600.6260 ; 5.1.2600.6260 (xpsp_sp3_gdr.120706-1619) ; Net Win32 API DLL ; Microsoft Corporation ; 337 920 ; 06.Jul.2012 16:58:52 ; C:\WINDOWS\system32\NETAPI32.dll ; WTSAPI32.dll ; 76F50000 - 76F58000 ; 00008000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1427) ; Windows Terminal Server SDK APIs ; Microsoft Corporation ; 18 432 ; 01.Dec.2007 01:26:10 ; C:\WINDOWS\system32\WTSAPI32.dll ; SETUPAPI.dll ; 77920000 - 77A13000 ; 000F3000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1427) ; Windows Setup API ; Microsoft Corporation ; 985 088 ; 01.Dec.2007 01:25:54 ; C:\WINDOWS\system32\SETUPAPI.dll ; Apphelp.dll ; 77B40000 - 77B62000 ; 00022000 ; Microsoft® Windows® Operating System ; 5.1.2600.3264 ; 5.1.2600.3264 (xpsp.071130-1425) ; Application Compatibility Client Library ; Microsoft Corporation ; 125 952 ; 01.Dec.2007 01:25:30 ; C:\WINDOWS\system32\Apphelp.dll ; All Threads: 824 ; CCProxy.exe+0x747de ; 00130000 ; 0012D000 ; 00003000 ; 194 ; Executive ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.080 ; 1196 ; CCProxy.dll+0x3cc20 ; 00F30000 ; 00F2C000 ; 00004000 ; 34 505 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.060 ; 00:00:00.010 ; 600 ; CCProxy.dll+0x3cc20 ; 01030000 ; 01020000 ; 00010000 ; 306 076 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.300 ; 00:00:01.802 ; 1200 ; CCProxy.dll+0x3cc20 ; 01130000 ; 01128000 ; 00008000 ; 318 096 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.300 ; 00:00:01.622 ; 968 ; CCProxy.dll+0x3cc20 ; 01230000 ; 01229000 ; 00007000 ; 4 760 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.170 ; 00:00:00.230 ; 1204 ; CCProxy.dll+0x3cc20 ; 01330000 ; 0132D000 ; 00003000 ; 7 899 ; UserRequest ; 8 ; 9 ; 25.Sep.2016 11:56:17 ; 00:00:00.010 ; 00:00:00.010 ; 956 ; CCProxy.dll+0x3cc20 ; 01430000 ; 01424000 ; 0000C000 ; 296 253 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.130 ; 00:00:00.771 ; 1208 ; CCProxy.dll+0x3cc20 ; 01530000 ; 01524000 ; 0000C000 ; 287 512 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.080 ; 00:00:00.470 ; 1228 ; CCProxy.dll+0x3cc20 ; 01630000 ; 01624000 ; 0000C000 ; 290 436 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.040 ; 00:00:00.040 ; 1240 ; CCProxy.dll+0x3cc20 ; 01730000 ; 01724000 ; 0000C000 ; 297 425 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.010 ; 00:00:00.050 ; 1232 ; CCProxy.dll+0x3cc20 ; 01830000 ; 01824000 ; 0000C000 ; 287 158 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 11:56:17 ; 00:00:00.020 ; 00:00:00.240 ; 1236 ; CCProxy.dll+0x1d5f0 ; 01930000 ; 0192F000 ; 00001000 ; 7 857 ; UserRequest ; 8 ; 9 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.010 ; 120 ; ADVAPI32.dll!CryptVerifySignatureW+0x17 ; 01B40000 ; 01B3F000 ; 00001000 ; 4 ; UserRequest ; 8 ; 9 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.000 ; 700 ; CCProxy.dll+0x1d5f0 ; 01C40000 ; 01C3E000 ; 00002000 ; 8 068 ; UserRequest ; 8 ; 10 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.000 ; 528 ; CCProxy.dll+0x1d5f0 ; 01D40000 ; 01D3E000 ; 00002000 ; 8 147 ; UserRequest ; 8 ; 9 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.010 ; 708 ; CCProxy.dll+0x1d5f0 ; 01E40000 ; 01E3E000 ; 00002000 ; 8 294 ; UserRequest ; 8 ; 10 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.000 ; 920 ; CCProxy.dll+0x1d5f0 ; 01F40000 ; 01F3E000 ; 00002000 ; 7 951 ; UserRequest ; 8 ; 10 ; 25.Sep.2016 11:56:17 ; 00:00:00.000 ; 00:00:00.010 ; 2316 ; CCProxy.dll+0x3cc20 ; 00D10000 ; 00D04000 ; 0000C000 ; 138 455 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.040 ; 00:00:00.260 ; 3032 ; CCProxy.dll+0x3cc20 ; 02060000 ; 02054000 ; 0000C000 ; 144 446 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.050 ; 00:00:00.130 ; 3036 ; CCProxy.dll+0x3cc20 ; 02160000 ; 02154000 ; 0000C000 ; 150 070 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.020 ; 00:00:00.030 ; 3040 ; CCProxy.dll+0x3cc20 ; 02260000 ; 02254000 ; 0000C000 ; 143 636 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.040 ; 00:00:00.030 ; 3048 ; CCProxy.dll+0x3cc20 ; 02360000 ; 02354000 ; 0000C000 ; 155 729 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.040 ; 00:00:00.040 ; 3056 ; CCProxy.dll+0x3cc20 ; 02460000 ; 02454000 ; 0000C000 ; 145 839 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.010 ; 00:00:00.320 ; 644 ; CCProxy.dll+0x3cc20 ; 02560000 ; 02554000 ; 0000C000 ; 157 993 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.020 ; 00:00:00.160 ; 608 ; CCProxy.dll+0x3cc20 ; 02660000 ; 02654000 ; 0000C000 ; 158 433 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.040 ; 00:00:00.020 ; 604 ; CCProxy.dll+0x3cc20 ; 02760000 ; 02754000 ; 0000C000 ; 158 439 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.020 ; 00:00:00.010 ; 3012 ; CCProxy.dll+0x3cc20 ; 02860000 ; 02854000 ; 0000C000 ; 140 917 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:26:03 ; 00:00:00.020 ; 00:00:00.140 ; 1496 ; CCProxy.dll+0x3cc20 ; 02960000 ; 02954000 ; 0000C000 ; 119 387 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.010 ; 00:00:00.630 ; 1172 ; CCProxy.dll+0x3cc20 ; 02A60000 ; 02A54000 ; 0000C000 ; 156 732 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.000 ; 00:00:00.010 ; 3632 ; CCProxy.dll+0x3cc20 ; 02B60000 ; 02B54000 ; 0000C000 ; 156 736 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.000 ; 00:00:00.050 ; 2168 ; CCProxy.dll+0x3cc20 ; 02C60000 ; 02C54000 ; 0000C000 ; 156 752 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.020 ; 00:00:00.030 ; 3508 ; CCProxy.dll+0x3cc20 ; 02D60000 ; 02D54000 ; 0000C000 ; 156 772 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.010 ; 00:00:00.040 ; 2172 ; CCProxy.dll+0x3cc20 ; 02E60000 ; 02E54000 ; 0000C000 ; 156 781 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.010 ; 00:00:00.030 ; 1192 ; CCProxy.dll+0x3cc20 ; 02F60000 ; 02F54000 ; 0000C000 ; 156 747 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.030 ; 00:00:00.030 ; 560 ; CCProxy.dll+0x3cc20 ; 03060000 ; 03054000 ; 0000C000 ; 156 598 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.020 ; 00:00:00.020 ; 2152 ; CCProxy.dll+0x3cc20 ; 03160000 ; 03154000 ; 0000C000 ; 150 922 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.010 ; 00:00:00.040 ; 2148 ; CCProxy.dll+0x3cc20 ; 03260000 ; 03254000 ; 0000C000 ; 156 739 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:04 ; 00:00:00.000 ; 00:00:00.010 ; 3088 ; CCProxy.dll+0x3cc20 ; 03360000 ; 03354000 ; 0000C000 ; 155 633 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.010 ; 00:00:00.000 ; 3100 ; CCProxy.dll+0x3cc20 ; 03460000 ; 03454000 ; 0000C000 ; 155 875 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.000 ; 00:00:00.010 ; 2468 ; CCProxy.dll+0x3cc20 ; 03560000 ; 03554000 ; 0000C000 ; 155 626 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.020 ; 00:00:00.010 ; 2780 ; CCProxy.dll+0x3cc20 ; 03660000 ; 03654000 ; 0000C000 ; 155 621 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.010 ; 00:00:00.000 ; 3328 ; CCProxy.dll+0x3cc20 ; 03760000 ; 03754000 ; 0000C000 ; 155 625 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.030 ; 00:00:00.010 ; 3848 ; CCProxy.dll+0x3cc20 ; 03860000 ; 03854000 ; 0000C000 ; 155 901 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.020 ; 00:00:00.010 ; 3372 ; CCProxy.dll+0x3cc20 ; 03960000 ; 03954000 ; 0000C000 ; 155 975 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.050 ; 00:00:00.010 ; 4064 ; CCProxy.dll+0x3cc20 ; 03A60000 ; 03A54000 ; 0000C000 ; 155 213 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.010 ; 00:00:00.030 ; 2260 ; CCProxy.dll+0x3cc20 ; 03B60000 ; 03B54000 ; 0000C000 ; 155 215 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.000 ; 00:00:00.030 ; 3132 ; CCProxy.dll+0x3cc20 ; 03C60000 ; 03C54000 ; 0000C000 ; 155 884 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:23 ; 00:00:00.010 ; 00:00:00.020 ; 3320 ; CCProxy.dll+0x3cc20 ; 03D60000 ; 03D54000 ; 0000C000 ; 150 093 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.040 ; 00:00:00.000 ; 804 ; CCProxy.dll+0x3cc20 ; 03E60000 ; 03E54000 ; 0000C000 ; 155 945 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.040 ; 00:00:00.000 ; 232 ; CCProxy.dll+0x3cc20 ; 03F60000 ; 03F5F000 ; 00001000 ; 155 969 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.010 ; 00:00:00.040 ; 4040 ; CCProxy.dll+0x3cc20 ; 04060000 ; 0405F000 ; 00001000 ; 155 967 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.010 ; 00:00:00.020 ; 2096 ; CCProxy.dll+0x3cc20 ; 04160000 ; 0415F000 ; 00001000 ; 155 959 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.020 ; 00:00:00.020 ; 2088 ; CCProxy.dll+0x3cc20 ; 04260000 ; 0425F000 ; 00001000 ; 155 967 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.030 ; 00:00:00.000 ; 3268 ; CCProxy.dll+0x3cc20 ; 04360000 ; 0435F000 ; 00001000 ; 155 965 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.010 ; 00:00:00.060 ; 3052 ; CCProxy.dll+0x3cc20 ; 04460000 ; 0445F000 ; 00001000 ; 155 961 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.010 ; 00:00:00.000 ; 3324 ; CCProxy.dll+0x3cc20 ; 04560000 ; 0455F000 ; 00001000 ; 155 974 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.020 ; 00:00:00.030 ; 2680 ; CCProxy.dll+0x3cc20 ; 04660000 ; 0465F000 ; 00001000 ; 155 974 ; DelayExecution ; 8 ; 8 ; 25.Sep.2016 12:27:24 ; 00:00:00.020 ; 00:00:00.030 ; 3108 ; ManageACL_32.exe+0x23a1d ; 00140000 ; 0013B000 ; 00005000 ; 242 ; UserRequest ; 8 ; 8 ; 25.Sep.2016 13:00:08 ; 00:00:00.010 ; 00:00:00.100 ; 3704 ; ADVAPI32.dll!WmiFreeBuffer+0xa7 ; 00B80000 ; 00B7F000 ; 00001000 ; 5 ; UserRequest ; 8 ; 8 ; 25.Sep.2016 13:00:08 ; 00:00:00.000 ; 00:00:00.000 ; Full Stack Data: 0013B4CC 7C948744 ntdll.dll!LdrAlternateResourcesEnabled+0x5 0013B4D0 7C911E7F ntdll.dll!LdrLoadAlternateResourceModule+0x5f 0013B4D4 003C0000 -> 40 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 0013B4D8 00000000 0013B4DC 0013C4B0 0013B4E0 00000000 0013B4E4 0013C4B8 0013B4E8 00000000 0013B4EC 00000000 0013B4F0 00000000 0013B4F4 00000000 0013B4F8 00000000 0013B4FC 00000000 0013B500 00000000 0013B504 00000000 0013B508 00000000 0013B50C 00000000 0013B510 00000000 0013B514 00000000 0013B518 00000000 0013B51C 00000000 0013B520 00000000 0013B524 00000000 0013B528 00000000 0013B52C 00000000 0013B530 00000000 0013B534 00000000 0013B538 00000000 0013B53C 00000000 0013B540 00000000 0013B544 00000000 0013B548 00000000 0013B54C 00000000 0013B550 00000000 0013B554 00000000 0013B558 00000000 0013B55C 00000000 0013B560 00000000 0013B564 00000000 0013B568 00000000 0013B56C 00000000 0013B570 00000000 0013B574 003C0001 -> 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013B578 00000000 0013B57C 003C0001 -> 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013B580 00000000 0013B584 00000000 0013B588 00000000 0013B58C 00000000 0013B590 00000000 0013B594 00000000 0013B598 00000000 0013B59C 00000000 0013B5A0 00000000 0013B5A4 00000000 0013B5A8 00000000 0013B5AC 00000000 0013B5B0 00000000 0013B5B4 00000000 0013B5B8 00000000 0013B5BC 00000000 0013B5C0 00000000 0013B5C4 00000000 0013B5C8 00000000 0013B5CC 00000000 0013B5D0 00000000 0013B5D4 00000000 0013B5D8 00000000 0013B5DC 00000000 0013B5E0 00000000 0013B5E4 00000000 0013B5E8 00000000 0013B5EC 00000000 0013B5F0 00000000 0013B5F4 00000000 0013B5F8 00000000 0013B5FC 00000000 0013B600 00000000 0013B604 00000000 0013B608 00000000 0013B60C 00000000 0013B610 00000000 0013B614 00000000 0013B618 00000000 0013B61C 00000000 0013B620 00000000 0013B624 00000000 0013B628 00000000 0013B62C 00000000 0013B630 00000000 0013B634 00000000 0013B638 00000000 0013B63C 00000000 0013B640 00000000 0013B644 00000000 0013B648 00000000 0013B64C 00000000 0013B650 00000000 0013B654 00000000 0013B658 00000000 0013B65C 00000000 0013B660 00000000 0013B664 00000000 0013B668 00000000 0013B66C 00000000 0013B670 00000000 0013B674 00000000 0013B678 00000000 0013B67C 00000000 0013B680 00000000 0013B684 00000000 0013B688 00000000 0013B68C 00000000 0013B690 00000000 0013B694 00000000 0013B698 00000000 0013B69C 00000000 0013B6A0 00000000 0013B6A4 00000000 0013B6A8 00000000 0013B6AC 00000000 0013B6B0 00000000 0013B6B4 00000000 0013B6B8 00000000 0013B6BC 00000000 0013B6C0 00000000 0013B6C4 00000000 0013B6C8 00000000 0013B6CC 00000000 0013B6D0 00000000 0013B6D4 00000000 0013B6D8 00000000 0013B6DC 00000000 0013B6E0 00000000 0013B6E4 00000000 0013B6E8 00000000 0013B6EC 00000000 0013B6F0 00000000 0013B6F4 00000000 0013B6F8 00000000 0013B6FC 00000000 0013B700 00000000 0013B704 00000000 0013B708 00000000 0013B70C 00000000 0013B710 00000000 0013B714 00000000 0013B718 00000000 0013B71C 00000000 0013B720 00000000 0013B724 00000000 0013B728 00000000 0013B72C 00000000 0013B730 00000000 0013B734 00000000 0013B738 00000000 0013B73C 00000000 0013B740 00000000 0013B744 00000000 0013B748 00000000 0013B74C 00000000 0013B750 00000000 0013B754 00000000 0013B758 00000000 0013B75C 00000000 0013B760 00000000 0013B764 00000000 0013B768 00000000 0013B76C 00000000 0013B770 00000000 0013B774 00000000 0013B778 00000000 0013B77C 00000000 0013B780 00000000 0013B784 00000000 0013B788 00000000 0013B78C 00000000 0013B790 00000000 0013B794 00000000 0013B798 00000000 0013B79C 00000000 0013B7A0 00000000 0013B7A4 00000000 0013B7A8 00000000 0013B7AC 00000000 0013B7B0 00000000 0013B7B4 00000000 0013B7B8 00000000 0013B7BC 00000000 0013B7C0 00000000 0013B7C4 00000000 0013B7C8 00000000 0013B7CC 00000000 0013B7D0 00000000 0013B7D4 00000000 0013B7D8 00000000 0013B7DC 00000000 0013B7E0 00000000 0013B7E4 00000000 0013B7E8 00000000 0013B7EC 00000000 0013B7F0 00000000 0013B7F4 00000000 0013B7F8 00000000 0013B7FC 0013B818 0013B800 7C915199 ntdll.dll!bsearch+0x46 0013B804 0013B840 0013B808 001400E4 -> 02 00 00 00 C8 10 00 00 2C 03 00 00 01 00 00 00 0013B80C 00000004 0013B810 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013B814 00140000 -> Actx 0013B818 0013B858 0013B81C 7C91538B ntdll.dll!bsearch+0x238 0013B820 0013B840 0013B824 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013B828 00000000 0013B82C 00000010 0013B830 00000000 0013B834 0013B8DC 0013B838 001410C8 -> SsHd, 0013B83C F46857D4 0013B840 0013B890 0013B844 7C915721 ntdll.dll!RtlHashUnicodeString+0x164 0013B848 0013B974 0013B84C 00000000 0013B850 00000001 0013B854 0013B8E4 0013B858 001410C8 -> SsHd, 0013B85C C0150008 0013B860 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013B864 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013B868 00261F54 -> C4 2D 26 00 E8 E2 97 7C 7D F2 00 4D 00 00 00 00 0013B86C 0013BB28 0013B870 7C915ED5 ntdll.dll!RtlValidateUnicodeString+0x10b 0013B874 7C92041E ntdll.dll!RtlInitMemoryStream+0x4c2 0013B878 7FFDFC12 -> 64 00 6C 00 6C 00 00 00 65 00 64 00 00 00 61 00 0013B87C 7C915F0C ntdll.dll!RtlValidateUnicodeString+0x142 0013B880 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013B884 00261FC0 -> ` & 0013B888 00000000 0013B88C 0013B8FC 0013B890 0013B8E8 0013B894 0013B89C 0013B898 001410C8 -> SsHd, 0013B89C 00000000 0013B8A0 0013B8EC 0013B8A4 7C91554D ntdll.dll!RtlFindActivationContextSectionString+0xdc 0013B8A8 0013B8C4 0013B8AC 7C97E2E8 ntdll.dll!NlsMbOemCodePageTag+0x240 0013B8B0 0013B8E8 0013B8B4 0013B8D0 0013B8B8 7C915199 ntdll.dll!bsearch+0x46 0013B8BC 0013B8F8 0013B8C0 001400E4 -> 02 00 00 00 C8 10 00 00 2C 03 00 00 01 00 00 00 0013B8C4 00000004 0013B8C8 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013B8CC 00140000 -> Actx 0013B8D0 0013B910 0013B8D4 7C91538B ntdll.dll!bsearch+0x238 0013B8D8 0013B8F8 0013B8DC 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013B8E0 00000000 0013B8E4 00000010 0013B8E8 00000000 0013B8EC 0013B994 0013B8F0 001410C8 -> SsHd, 0013B8F4 F46857D4 0013B8F8 0013B948 0013B8FC 7C915721 ntdll.dll!RtlHashUnicodeString+0x164 0013B900 0013BA2C 0013B904 00000000 0013B908 00000001 0013B90C 0013B99C 0013B910 001410C8 -> SsHd, 0013B914 C0150008 0013B918 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013B91C 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013B920 00261F54 -> C4 2D 26 00 E8 E2 97 7C 7D F2 00 4D 00 00 00 00 0013B924 0013BBE0 0013B928 7C915ED5 ntdll.dll!RtlValidateUnicodeString+0x10b 0013B92C 7C92041E ntdll.dll!RtlInitMemoryStream+0x4c2 0013B930 7FFDFC12 -> 64 00 6C 00 6C 00 00 00 65 00 64 00 00 00 61 00 0013B934 7C915F0C ntdll.dll!RtlValidateUnicodeString+0x142 0013B938 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013B93C 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013B940 00000000 0013B944 0013B9B4 0013B948 0013B9A0 0013B94C 0013B954 0013B950 001410C8 -> SsHd, 0013B954 00000000 0013B958 0013B9A4 0013B95C 7C91554D ntdll.dll!RtlFindActivationContextSectionString+0xdc 0013B960 0013B97C 0013B964 7C97E2E8 ntdll.dll!NlsMbOemCodePageTag+0x240 0013B968 0013B9A0 0013B96C 0013B998 0013B970 0013BA08 0013B974 0013BAD4 0013B978 00000000 0013B97C 00000018 0013B980 00000003 0013B984 0013BC7C 0013B988 00000000 0013B98C 00000003 0013B990 00000002 0013B994 00000001 0013B998 00000000 0013B99C 00000000 0013B9A0 0000032C 0013B9A4 0013BA68 0013B9A8 7C915C49 ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x34e 0013B9AC 01000003 0013B9B0 00000000 0013B9B4 001410C8 -> SsHd, 0013B9B8 0013BA2C 0013B9BC 0013B9C8 0013B9C0 7C97E380 ntdll.dll!NlsMbOemCodePageTag+0x2d8 0013B9C4 7C915CA7 ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x3ac 0013B9C8 0013B9FC 0013B9CC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013B9D0 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013B9D4 00000045 0013B9D8 00161378 -> 98 85 16 00 02 00 D9 01 04 00 00 01 DA 01 00 00 0013B9DC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013B9E0 0017ABE0 -> 00 00 00 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013B9E4 0013B9D4 0013B9E8 0017ABE0 -> 00 00 00 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013B9EC 0013BC18 0013B9F0 7C90E920 ntdll.dll!strchr+0x113 0013B9F4 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013B9F8 FFFFFFFF 0013B9FC 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BA00 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013BA04 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013BA08 00000000 0013BA0C 0013BF34 0013BA10 0013BF28 0013BA14 0013BF3C 0013BA18 0013BF30 0013BA1C 00000000 0013BA20 00000000 0013BA24 0013BA94 0013BA28 00000000 0013BA2C 020A0012 0013BA30 7FFDFC00 -> advapi32.dll 0013BA34 00002E58 0013BA38 00000000 0013BA3C 7C91585F ntdll.dll!RtlHashUnicodeString+0x2a2 0013BA40 00020000 0013BA44 0013BA60 0013BA48 0013BA60 0013BA4C 0013BA60 0013BA50 00000002 0013BA54 00000002 0013BA58 7C910385 ntdll.dll!RtlImageDirectoryEntryToData+0x3f 0013BA5C 7C900000 ntdll.dll+0x0 0013BA60 00000000 0013BA64 00002E58 0013BA68 0013BBD0 0013BA6C 0013BB08 0013BA70 0013BBD0 0013BA74 7C915B58 ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x25d 0013BA78 0013BABC 0013BA7C 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013BA80 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013BA84 7C915BBD ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x2c2 0013BA88 7C916E86 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x209 0013BA8C 7C97E380 ntdll.dll!NlsMbOemCodePageTag+0x2d8 0013BA90 00261FC0 -> ` & 0013BA94 00000000 0013BA98 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013BA9C 0013BC2C 0013BAA0 00000000 0013BAA4 0013BC84 0013BAA8 00000000 0013BAAC 0013BCB4 -> WS\system32\dwwin.exe 0013BAB0 00000000 0013BAB4 0013BB2C 0013BAB8 00000000 0013BABC 00000000 0013BAC0 00000000 0013BAC4 020A0012 0013BAC8 7FFDFC00 -> advapi32.dll 0013BACC 00000000 0013BAD0 0013BAC0 0013BAD4 00000000 0013BAD8 00000000 0013BADC 00000000 0013BAE0 00000000 0013BAE4 00000000 0013BAE8 00000000 0013BAEC 00000000 0013BAF0 00000000 0013BAF4 00000000 0013BAF8 00000000 0013BAFC 7C916F01 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x284 0013BB00 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013BB04 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013BB08 0013BBE8 0013BB0C 7C916F0D ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x290 0013BB10 0013BB50 0013BB14 7C90EADC ntdll.dll!strchr+0x2cf 0013BB18 0013BBD8 0013BB1C 7C90EA41 ntdll.dll!strchr+0x234 0013BB20 FFFFFFFF 0013BB24 0013BBD8 0013BB28 0013BBE8 0013BB2C 0013BB64 0013BB30 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013BB34 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013BB38 0013BEAC 0013BB3C 00020024 0013BB40 0013BC7C 0013BB44 00000002 0013BB48 0013BB68 0013BB4C 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013BB50 7C901000 ntdll.dll!RtlEnterCriticalSection 0013BB54 0013BB38 0013BB58 00000000 0013BB5C 0013BC0C 0013BB60 7C90E920 ntdll.dll!strchr+0x113 0013BB64 7C910460 ntdll.dll!RtlReleasePebLock+0xf 0013BB68 7C980620 ntdll.dll!NlsMbOemCodePageTag+0x2578 0013BB6C 7C913F92 ntdll.dll!RtlDetermineDosPathNameType_U+0x4d0 0013BB70 7C913F85 ntdll.dll!RtlDetermineDosPathNameType_U+0x4c3 0013BB74 00000208 0013BB78 0013BF34 0013BB7C 0013BF28 0013BB80 FFFFFFFF 0013BB84 0000003A 0013BB88 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013BB8C 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013BB90 00000000 0013BB94 0013C0BC 0013BB98 0013BCA2 0013BB9C 00000002 0013BBA0 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013BBA4 0017B120 -> C:\WINDOWS\system32\dwwin.exe 0013BBA8 00000000 0013BBAC 0017B120 -> C:\WINDOWS\system32\dwwin.exe 0013BBB0 0000001D 0013BBB4 0017B120 -> C:\WINDOWS\system32\dwwin.exe 0013BBB8 0000001D 0013BBBC 00000000 0013BBC0 00000003 0013BBC4 0208003A 0013BBC8 00000003 0013BBCC 4308003A 0013BBD0 0013BCA4 0013BBD4 0000003A 0013BBD8 00000000 0013BBDC 0013BCDE 0013BBE0 01000000 0013BBE4 00000000 0013BBE8 5613BC1C 0013BBEC 00000000 0013BBF0 00000000 0013BBF4 0017B15A -> 00 00 00 00 00 00 20 00 42 00 EE 01 0E 00 00 00 0013BBF8 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013BBFC 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013BC00 00002E58 0013BC04 0013BB74 0013BC08 0013BF28 0013BC0C 0013BEBC 0013BC10 7C90E920 ntdll.dll!strchr+0x113 0013BC14 0013BF34 0013BC18 00000008 0013BC1C 0013BECC 0013BC20 7C914152 ntdll.dll!RtlDetermineDosPathNameType_U+0x690 0013BC24 0017ABE8 -> C:\WINDOWS\system32 0013BC28 0013BCA4 0013BC2C 7C910460 ntdll.dll!RtlReleasePebLock+0xf 0013BC30 7C980620 ntdll.dll!NlsMbOemCodePageTag+0x2578 0013BC34 7C914217 ntdll.dll!RtlDetermineDosPathNameType_U+0x755 0013BC38 7C9141DF ntdll.dll!RtlDetermineDosPathNameType_U+0x71d 0013BC3C 0013C1D8 0013BC40 0013BC74 0013BC44 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013BC48 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BC4C 00000045 0013BC50 00161378 -> 98 85 16 00 02 00 D9 01 04 00 00 01 DA 01 00 00 0013BC54 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013BC58 0017ABE0 -> 00 00 00 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013BC5C 0013BC4C 0013BC60 7C913FAC ntdll.dll!RtlDetermineDosPathNameType_U+0x4ea 0013BC64 0013BE90 0013BC68 7C90E920 ntdll.dll!strchr+0x113 0013BC6C 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013BC70 FFFFFFFF 0013BC74 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BC78 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013BC7C 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013BC80 0013C1D8 0013BC84 0013C1DC 0013BC88 0013C1B0 0013BC8C 7C90E920 ntdll.dll!strchr+0x113 0013BC90 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013BC94 FFFFFFFF 0013BC98 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BC9C 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013BCA0 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013BCA4 00000000 0013BCA8 0013C1EC 0013BCAC 0013C1C4 0013BCB0 004F0044 0013BCB4 00530057 0013BCB8 0073005C 0013BCBC 00730079 0013BCC0 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BCC4 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BCC8 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BCCC 00770064 0013BCD0 00690077 -> trackbar32 0013BCD4 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013BCD8 00780065 0013BCDC 00000065 0013BCE0 00000000 0013BCE4 00000000 0013BCE8 00000000 0013BCEC 00000000 0013BCF0 00000000 0013BCF4 00000000 0013BCF8 00000000 0013BCFC 00000000 0013BD00 00000000 0013BD04 00000000 0013BD08 00000000 0013BD0C 00000000 0013BD10 00000000 0013BD14 00000000 0013BD18 00000000 0013BD1C 00000000 0013BD20 00000000 0013BD24 00000000 0013BD28 00000000 0013BD2C 00000000 0013BD30 00000000 0013BD34 00000000 0013BD38 00000000 0013BD3C 00000000 0013BD40 00000000 0013BD44 00000000 0013BD48 00000000 0013BD4C 00000000 0013BD50 00000000 0013BD54 00000000 0013BD58 00000000 0013BD5C 00000000 0013BD60 00000000 0013BD64 00000000 0013BD68 00000000 0013BD6C 00000000 0013BD70 00000000 0013BD74 00000000 0013BD78 00000000 0013BD7C 00000000 0013BD80 00000000 0013BD84 00000000 0013BD88 00000000 0013BD8C 00000000 0013BD90 00000000 0013BD94 00000000 0013BD98 00000000 0013BD9C 00000000 0013BDA0 00000000 0013BDA4 00000000 0013BDA8 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013BDAC 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013BDB0 0013C124 0013BDB4 00020024 0013BDB8 0013BEF4 0013BDBC 00000002 0013BDC0 0013BDE0 0013BDC4 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013BDC8 7C901000 ntdll.dll!RtlEnterCriticalSection 0013BDCC 0013BDB0 0013BDD0 00000000 0013BDD4 0013BE84 0013BDD8 7C90E920 ntdll.dll!strchr+0x113 0013BDDC 7C910460 ntdll.dll!RtlReleasePebLock+0xf 0013BDE0 7C980620 ntdll.dll!NlsMbOemCodePageTag+0x2578 0013BDE4 7C913F92 ntdll.dll!RtlDetermineDosPathNameType_U+0x4d0 0013BDE8 7C913F85 ntdll.dll!RtlDetermineDosPathNameType_U+0x4c3 0013BDEC 00000208 0013BDF0 0013C1DC 0013BDF4 0013C1B0 0013BDF8 0013BEA8 0013BDFC 0000003A 0013BE00 7C910460 ntdll.dll!RtlReleasePebLock+0xf 0013BE04 7C980620 ntdll.dll!NlsMbOemCodePageTag+0x2578 0013BE08 7C913F92 ntdll.dll!RtlDetermineDosPathNameType_U+0x4d0 0013BE0C 7C913F85 ntdll.dll!RtlDetermineDosPathNameType_U+0x4c3 0013BE10 0013BF1A 0013BE14 00000002 0013BE18 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013BE1C 0017AE08 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013BE20 0013C1D8 0013BE24 00000000 0013BE28 0000001D 0013BE2C 0017AE08 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013BE30 00000000 0013BE34 00000000 0013BE38 00000003 0013BE3C 0208003A 0013BE40 0013C260 0013BE44 43000000 0013BE48 0013BF1C 0013BE4C 0000003A 0013BE50 00000000 0013BE54 0013BF44 -> dwwin.exe 0013BE58 01000000 0013BE5C 00000000 0013BE60 5608003A 0013BE64 00000000 0013BE68 00000000 0013BE6C 0013BF42 0013BE70 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013BE74 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013BE78 0013BEAC 0013BE7C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013BE80 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BE84 00000005 0013BE88 00160778 -> 30 E4 16 00 03 00 49 00 04 00 00 01 23 01 00 00 0013BE8C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013BE90 0016E430 -> 88 E8 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BE94 0013BE84 0013BE98 7C90FEAE ntdll.dll!RtlInitUnicodeStringEx+0x19 0013BE9C 0013C0C8 0013BEA0 7C90E920 ntdll.dll!strchr+0x113 0013BEA4 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013BEA8 FFFFFFFF 0013BEAC 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BEB0 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013BEB4 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013BEB8 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BEBC 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BEC0 00000000 0013BEC4 00000001 0013BEC8 00000002 0013BECC 7C918067 ntdll.dll!RtlAnsiCharToUnicodeChar+0x36 0013BED0 00000000 0013BED4 000A0008 0013BED8 7C913FAC ntdll.dll!RtlDetermineDosPathNameType_U+0x4ea 0013BEDC 00000000 0013BEE0 0013C1D8 0013BEE4 0000021A 0013BEE8 00140012 -> 00 00 00 00 00 00 20 00 00 00 00 00 00 00 14 00 0013BEEC 0013BF44 -> dwwin.exe 0013BEF0 0000003A 0013BEF4 00000002 0013BEF8 0013BF2C 0013BEFC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013BF00 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BF04 00000007 0013BF08 001607D8 -> 48 D9 16 00 04 00 38 00 04 00 00 01 41 00 00 00 0013BF0C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013BF10 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013BF14 0013BF04 0013BF18 01000022 0013BF1C 0013C148 0013BF20 7C90E920 ntdll.dll!strchr+0x113 0013BF24 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013BF28 FFFFFFFF 0013BF2C 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013BF30 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013BF34 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013BF38 00000000 0013BF3C 0013C4D4 0013BF40 7C9020F5 ntdll.dll!memmove 0013BF44 00770064 0013BF48 00690077 -> trackbar32 0013BF4C 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013BF50 00780065 0013BF54 00000065 0013BF58 00000000 0013BF5C 00000000 0013BF60 00000000 0013BF64 00000000 0013BF68 00000000 0013BF6C 00000000 0013BF70 00000000 0013BF74 00000000 0013BF78 00000000 0013BF7C 00000000 0013BF80 00000000 0013BF84 00000000 0013BF88 00000000 0013BF8C 00000000 0013BF90 00000000 0013BF94 00000000 0013BF98 00000000 0013BF9C 00000000 0013BFA0 00000000 0013BFA4 00000000 0013BFA8 00000000 0013BFAC 00000000 0013BFB0 00000000 0013BFB4 00000000 0013BFB8 00000000 0013BFBC 00000000 0013BFC0 00000000 0013BFC4 00000000 0013BFC8 00000000 0013BFCC 00000000 0013BFD0 00000000 0013BFD4 00000000 0013BFD8 00000000 0013BFDC 00000000 0013BFE0 00000000 0013BFE4 00000000 0013BFE8 00000000 0013BFEC 00000000 0013BFF0 00000000 0013BFF4 00000000 0013BFF8 00000000 0013BFFC 00000000 0013C000 00000000 0013C004 00000000 0013C008 00000000 0013C00C 00000000 0013C010 00000000 0013C014 00000000 0013C018 00000000 0013C01C 00000000 0013C020 00000000 0013C024 00000000 0013C028 00000000 0013C02C 00000000 0013C030 00000000 0013C034 00000000 0013C038 00000000 0013C03C 00000000 0013C040 00000000 0013C044 00000000 0013C048 00000000 0013C04C 00000000 0013C050 00000000 0013C054 7C9115F9 ntdll.dll!RtlLogStackBackTrace+0x25 0013C058 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C05C 0016E430 -> 88 E8 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C060 00000000 0013C064 00000000 0013C068 00000000 0013C06C 00000000 0013C070 00000000 0013C074 00000005 0013C078 00000000 0013C07C 00000000 0013C080 00000000 0013C084 00000000 0013C088 00000000 0013C08C 00000000 0013C090 0013C0A0 0013C094 00000000 0013C098 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013C09C 0017ABD8 -> 45 00 43 00 B9 01 0E 00 00 00 00 00 3F 00 5C 00 0013C0A0 0013C16C 0013C0A4 00000000 0013C0A8 0016E430 -> 88 E8 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C0AC 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C0B0 00000000 0013C0B4 00000028 0013C0B8 00004021 0013C0BC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C0C0 0013BEB8 0013C0C4 00000000 0013C0C8 0013C10C 0013C0CC 7C90E920 ntdll.dll!strchr+0x113 0013C0D0 7C9101E0 ntdll.dll!RtlAllocateHeap+0x11c 0013C0D4 FFFFFFFF 0013C0D8 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013C0DC 7C9114D6 ntdll.dll!RtlDeleteCriticalSection+0x15c 0013C0E0 7C911514 ntdll.dll!RtlDeleteCriticalSection+0x19a 0013C0E4 7C97E120 ntdll.dll!NlsMbOemCodePageTag+0x78 0013C0E8 7C9114EA ntdll.dll!RtlDeleteCriticalSection+0x170 0013C0EC 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C0F0 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C0F4 00000000 0013C0F8 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013C0FC 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013C100 0016E430 -> 88 E8 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C104 0013C058 0013C108 00000000 0013C10C 0013C730 0013C110 7C90E920 ntdll.dll!strchr+0x113 0013C114 7C911600 ntdll.dll!RtlLogStackBackTrace+0x2c 0013C118 FFFFFFFF 0013C11C 7C9115C6 ntdll.dll!RtlInitializeCriticalSectionAndSpinCount+0xac 0013C120 7C97E140 ntdll.dll!NlsMbOemCodePageTag+0x98 0013C124 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C128 00000000 0013C12C 7C9020F5 ntdll.dll!memmove 0013C130 0013C474 0013C134 00000038 0013C138 7C00E920 0013C13C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C140 0013BF38 0013C144 7C9141DF ntdll.dll!RtlDetermineDosPathNameType_U+0x71d 0013C148 0013C730 0013C14C 7C90E920 ntdll.dll!strchr+0x113 0013C150 0013C160 0013C154 7C91162C ntdll.dll!RtlInitializeCriticalSection+0xf 0013C158 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C15C 00000000 0013C160 0013C174 0013C164 7C80EFD0 kernel32.dll!FindClose+0x134 0013C168 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C16C 00000000 0013C170 0013C4D4 0013C174 0013C458 0013C178 7C80EF73 kernel32.dll!FindClose+0xd7 0013C17C 00000728 0013C180 7C9020F5 ntdll.dll!memmove 0013C184 00000000 0013C188 7C80EE5E kernel32.dll!FindFirstFileExW+0x341 0013C18C 00000018 0013C190 00000000 0013C194 0013C1DC 0013C198 00000040 0013C19C 00000000 0013C1A0 00000000 0013C1A4 0013C4D4 0013C1A8 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013C1AC 0017ABE0 -> 00 00 00 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013C1B0 00000000 0013C1B4 00000000 0013C1B8 00000000 0013C1BC 00000000 0013C1C0 00000070 0013C1C4 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013C1C8 0017AE08 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013C1CC 00000000 0013C1D0 00530057 0013C1D4 00120012 0013C1D8 0017AC10 -> dwwin.exe 0013C1DC 00300030 -> 1C 05 25 02 1C 05 26 02 1C 05 27 02 1C 05 28 02 0013C1E0 0017ABE0 -> 00 00 00 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013C1E4 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C1E8 00000728 0013C1EC 00000000 0013C1F0 00000001 0013C1F4 9160E000 0013C1F8 01C47A1A 0013C1FC BAE6A640 0013C200 01CDBD1D 0013C204 0A42E800 0013C208 01C833A0 0013C20C 952ABD80 0013C210 01D21713 0013C214 0002C000 0013C218 00000000 0013C21C 00020000 0013C220 00000000 0013C224 00000820 0013C228 00000012 0013C22C 00000000 0013C230 00000000 0013C234 00000000 0013C238 00000000 0013C23C 00000000 0013C240 00000000 0013C244 00000000 0013C248 00640000 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C24C 00770077 0013C250 006E0069 -> 00 69 00 6E 00 65 00 5C 00 53 00 4F 00 46 00 54 0013C254 0065002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C258 00650078 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C25C 00000000 0013C260 00000000 0013C264 00000000 0013C268 00000000 0013C26C 00000000 0013C270 00000000 0013C274 00000000 0013C278 00000000 0013C27C 00000000 0013C280 00000000 0013C284 00000000 0013C288 00000000 0013C28C 00000000 0013C290 00000000 0013C294 00000000 0013C298 00000000 0013C29C 00000000 0013C2A0 00000000 0013C2A4 00000000 0013C2A8 00000000 0013C2AC 00000000 0013C2B0 00000000 0013C2B4 00000000 0013C2B8 00000000 0013C2BC 00000000 0013C2C0 00000000 0013C2C4 00000000 0013C2C8 00000000 0013C2CC 00000000 0013C2D0 00000000 0013C2D4 0013C2E4 0013C2D8 00000000 0013C2DC 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013C2E0 0016E428 -> 05 00 03 00 47 01 08 00 88 E8 16 00 00 00 00 00 0013C2E4 0013C3B0 0013C2E8 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013C2EC 00160778 -> 30 E4 16 00 03 00 49 00 04 00 00 01 23 01 00 00 0013C2F0 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C2F4 0016E450 -> 04 00 05 00 48 01 0C 00 55 00 6E 00 74 00 72 00 0013C2F8 0016E430 -> 88 E8 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C2FC 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C300 00000000 0013C304 00000000 0013C308 00000000 0013C30C 00000000 0013C310 00000000 0013C314 00000000 0013C318 00000000 0013C31C 00000000 0013C320 00000000 0013C324 00000000 0013C328 00000000 0013C32C 0013C33C 0013C330 00000000 0013C334 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013C338 0017ABD8 -> 45 00 43 00 B9 01 0E 00 00 00 00 00 3F 00 5C 00 0013C33C 0013C408 0013C340 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013C344 00161378 -> 98 85 16 00 02 00 D9 01 04 00 00 01 DA 01 00 00 0013C348 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C34C 0013C35C 0013C350 00000000 0013C354 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013C358 0016D940 -> 07 00 16 00 EA 01 0C 00 08 E3 16 00 00 00 00 00 0013C35C 0013C428 0013C360 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013C364 001607D8 -> 48 D9 16 00 04 00 38 00 04 00 00 01 41 00 00 00 0013C368 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C36C 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C370 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C374 00000000 0013C378 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C37C 00000000 0013C380 00000000 0013C384 00000000 0013C388 00000000 0013C38C 00000000 0013C390 00010000 0013C394 0013C3A4 0013C398 00000000 0013C39C 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013C3A0 0017AE00 -> 09 00 45 00 02 01 0C 00 00 00 00 00 5C 00 57 00 0013C3A4 0013C470 0013C3A8 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013C3AC 00160838 -> 08 AE 17 00 01 00 07 00 04 00 00 01 10 00 00 00 0013C3B0 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C3B4 7C9020F5 ntdll.dll!memmove 0013C3B8 00000000 0013C3BC 0017AE42 -> 00 00 73 00 65 00 21 00 09 00 0B 01 08 00 00 00 0013C3C0 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013C3C4 0016E450 -> 04 00 05 00 48 01 0C 00 55 00 6E 00 74 00 72 00 0013C3C8 00000038 0013C3CC 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C3D0 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013C3D4 0013C3C4 0013C3D8 0013C730 0013C3DC 0013C420 0013C3E0 7C90E920 ntdll.dll!strchr+0x113 0013C3E4 7C911468 ntdll.dll!RtlDeleteCriticalSection+0xee 0013C3E8 FFFFFFFF 0013C3EC 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013C3F0 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C3F4 7C9113F2 ntdll.dll!RtlDeleteCriticalSection+0x78 0013C3F8 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C3FC 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C400 00000000 0013C404 0016E868 -> 68 E1 97 7C 98 F8 16 00 00 00 00 00 00 00 00 00 0013C408 0001E168 0013C40C 00000007 0013C410 00000048 0013C414 00000000 0013C418 0013C46C 0013C41C 7C90E920 ntdll.dll!strchr+0x113 0013C420 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013C424 FFFFFFFF 0013C428 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C42C 7C80EF20 kernel32.dll!FindClose+0x84 0013C430 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C434 00000000 0013C438 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C43C 7C9020F5 ntdll.dll!memmove 0013C440 00000000 0013C444 0017AE42 -> 00 00 73 00 65 00 21 00 09 00 0B 01 08 00 00 00 0013C448 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013C44C 7C90D80A ntdll.dll!NtQueryInformationProcess+0xc 0013C450 7C80AD05 kernel32.dll!SetErrorMode+0x56 0013C454 FFFFFFFF 0013C458 0000000C 0013C45C 7C90DCAA ntdll.dll!NtSetInformationProcess+0xc 0013C460 7C80ACE1 kernel32.dll!SetErrorMode+0x32 0013C464 FFFFFFFF 0013C468 0000000C 0013C46C 0013C478 0013C470 00000004 0013C474 00000000 0013C478 00000001 0013C47C 0013C740 0013C480 7C81ECD1 kernel32.dll!GetLongPathNameW+0x2fa 0013C484 7C81ECE4 kernel32.dll!GetLongPathNameW+0x30d 0013C488 0013D07C 0013C48C 77DD0043 ADVAPI32.dll+0x43 0013C490 00000734 0013C494 0013C76E 0013C498 0013C4A8 0013C49C 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C4A0 00000000 0013C4A4 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013C4A8 0013C4DC 0013C4AC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C4B0 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013C4B4 00000009 0013C4B8 00160838 -> 08 AE 17 00 01 00 07 00 04 00 00 01 10 00 00 00 0013C4BC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C4C0 0017AE08 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013C4C4 0013C4B4 0013C4C8 0013C500 -> dwwin.exe 0013C4CC 0013C6F8 0013C4D0 7C90E920 ntdll.dll!strchr+0x113 0013C4D4 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013C4D8 FFFFFFFF 0013C4DC 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013C4E0 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013C4E4 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013C4E8 0013D07C 0013C4EC 0000003A 0013C4F0 0000003C 0013C4F4 0002C000 0013C4F8 0013C514 0013C4FC 00000020 0013C500 00770064 0013C504 00690077 -> trackbar32 0013C508 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013C50C 00780065 0013C510 00000065 0013C514 00000058 0013C518 0017B160 -> 20 00 42 00 EE 01 0E 00 00 00 00 00 45 00 47 00 0013C51C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C520 00000000 0013C524 00000100 0013C528 0017B160 -> 20 00 42 00 EE 01 0E 00 00 00 00 00 45 00 47 00 0013C52C 00000100 0013C530 0017B168 -> 00 00 00 00 45 00 47 00 49 00 53 00 54 00 52 00 0013C534 00010015 0013C538 00000017 0013C53C 7C914DF1 ntdll.dll!RtlConvertSidToUnicodeString+0x23c 0013C540 0013C642 0013C544 0013C830 0013C548 00000004 0013C54C 00000000 0013C550 FFFFFFFF 0013C554 0013C642 0013C558 0013C5F8 -> 5-21-1409082233-920026266-1708537768-1003 0013C55C 0013C4B8 0013C560 00000000 0013C564 0013C878 0013C568 7C90E920 ntdll.dll!strchr+0x113 0013C56C 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013C570 FFFFFFFF 0013C574 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C578 77B421CA Apphelp.dll+0x21ca 0013C57C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C580 00000000 0013C584 00370031 -> 00 08 06 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C588 00380030 -> 09 00 00 00 48 02 0A 00 48 00 10 02 0B 00 48 00 0013C58C 00330035 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C590 00300031 -> 05 25 02 1C 05 26 02 1C 05 27 02 1C 05 28 02 1C 0013C594 00330030 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C598 00350000 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C59C 00002E58 0013C5A0 0013C540 0013C5A4 0013C544 0013C5A8 0013DD50 0013C5AC 7C90E920 ntdll.dll!strchr+0x113 0013C5B0 7C914E08 ntdll.dll!RtlConvertSidToUnicodeString+0x253 0013C5B4 0000005C 0013C5B8 0013C830 0013C5BC 00000005 0013C5C0 0013C7F4 0013C5C4 7C914D12 ntdll.dll!RtlConvertSidToUnicodeString+0x15d 0013C5C8 001632BE -> S-1-5-21-1409082233-920026266-1708537768-1003 0013C5CC 0013C5E4 0013C5D0 00000000 0013C5D4 00000000 0013C5D8 7C914D1F ntdll.dll!RtlConvertSidToUnicodeString+0x16a 0013C5DC 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013C5E0 00140000 -> Actx 0013C5E4 005C005A -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C5E8 0013C5F0 -> S-1-5-21-1409082233-920026266-1708537768-1003 0013C5EC 0013C818 0013C5F0 002D0053 -> 02 72 02 77 02 7C 02 82 02 89 02 92 02 9A 02 A3 0013C5F4 002D0031 -> 02 0C 02 13 02 1C 02 22 02 29 02 30 02 38 02 3D 0013C5F8 002D0035 -> 02 1C 02 22 02 29 02 30 02 38 02 3D 02 41 02 45 0013C5FC 00310032 -> 02 02 D0 D0 02 02 D1 D0 02 02 D2 D0 02 02 D3 D0 0013C600 0031002D -> D0 02 02 CF D0 02 02 D0 D0 02 02 D1 D0 02 02 D2 0013C604 00300034 -> 1C 05 26 02 1C 05 27 02 1C 05 28 02 1C 05 29 02 0013C608 00300039 -> 05 27 02 1C 05 28 02 1C 05 29 02 1C 05 2A 02 1C 0013C60C 00320038 -> 71 94 02 02 72 94 02 02 73 94 02 02 74 94 02 02 0013C610 00330032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C614 002D0033 -> 02 13 02 1C 02 22 02 29 02 30 02 38 02 3D 02 41 0013C618 00320039 -> 94 02 02 72 94 02 02 73 94 02 02 74 94 02 02 75 0013C61C 00300030 -> 1C 05 25 02 1C 05 26 02 1C 05 27 02 1C 05 28 02 0013C620 00360032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C624 00360032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C628 002D0036 -> ȜȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013C62C 00370031 -> 00 08 06 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C630 00380030 -> 09 00 00 00 48 02 0A 00 48 00 10 02 0B 00 48 00 0013C634 00330035 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C638 00370037 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 98 05 37 0013C63C 00380036 -> 0A 00 48 00 10 02 0B 00 48 00 10 02 0B 00 48 04 0013C640 0031002D -> D0 02 02 CF D0 02 02 D0 D0 02 02 D1 D0 02 02 D2 0013C644 00300030 -> 1C 05 25 02 1C 05 26 02 1C 05 27 02 1C 05 28 02 0013C648 00000033 0013C64C 7C97EF02 -> stem32\dwwin.exe 0013C650 7C97F10A ntdll.dll!NlsMbOemCodePageTag+0x1062 0013C654 7C97EEE8 -> advapi32.dll 0013C658 0013C6C8 0013C65C 0013C6B4 0013C660 0013C668 0013C664 001410C8 -> SsHd, 0013C668 0013C69C 0013C66C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C670 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013C674 00000011 0013C678 001609B8 -> 68 66 17 00 01 00 03 00 04 00 00 01 0A 00 00 00 0013C67C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C680 00000000 0013C684 0013C674 0013C688 0013C7E8 0013C68C 0013C8B8 0013C690 7C90E920 ntdll.dll!strchr+0x113 0013C694 00000392 0013C698 0013C8C8 0013C69C 7C911028 ntdll.dll!wcsncpy+0xaa9 0013C6A0 7C911086 ntdll.dll!wcsncpy+0xb07 0013C6A4 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013C6A8 77E03C3C -> %HKEY_LOCAL_MACHINE 0013C6AC 0016D898 -> C:\WINDOWS\*.exe 0013C6B0 0017F658 -> FB ED 72 72 9F AF DF 4D B6 5B E4 28 2F 2D EE FC 0013C6B4 0000032C 0013C6B8 0013C77C 0013C6BC 7C915C49 ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x34e 0013C6C0 01000003 0013C6C4 00000000 0013C6C8 001410C8 -> SsHd, 0013C6CC 7C90D99A ntdll.dll!NtQueryVolumeInformationFile+0xc 0013C6D0 77DDA5DA ADVAPI32.dll!IdentifyCodeAuthzLevelW+0x712 0013C6D4 00000000 0013C6D8 0017AE08 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013C6DC 0013C6F0 0013C6E0 00000008 0013C6E4 00000048 0013C6E8 0000CBA4 0013C6EC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C6F0 0013C4E8 0013C6F4 77DDA591 ADVAPI32.dll!IdentifyCodeAuthzLevelW+0x6c9 0013C6F8 0013DD50 0013C6FC 7C90E920 ntdll.dll!strchr+0x113 0013C700 7C9101E0 ntdll.dll!RtlAllocateHeap+0x11c 0013C704 FFFFFFFF 0013C708 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013C70C 7C9104D4 ntdll.dll!RtlFreeAnsiString+0x6e 0013C710 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013C714 00000000 0013C718 0000003C 0013C71C 0013C740 0013C720 7C91F9FA ntdll.dll!RtlDuplicateUnicodeString+0x97 0013C724 0000003C 0013C728 0013D07C 0013C72C 77DD0043 ADVAPI32.dll+0x43 0013C730 00000734 0013C734 00000000 0013C738 0000003A 0013C73C 00000000 0013C740 0013CB80 -> ternet Files\OLK* 0013C744 77DDA343 ADVAPI32.dll!IdentifyCodeAuthzLevelW+0x47b 0013C748 00000001 0013C74C 0013C75C 0013C750 77DDA34B ADVAPI32.dll!IdentifyCodeAuthzLevelW+0x483 0013C754 00000000 0013C758 0000003A 0013C75C 001789C0 -> C8 B3 17 00 78 68 17 00 45 00 3E 00 0D 00 0A 00 0013C760 0013C974 -> Intern즜写粑진ä 0013C764 00000036 0013C768 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013C76C 00000000 0013C770 0013C8B0 0013C774 7C90D96E ntdll.dll!NtQueryValueKey 0013C778 0013C7F0 0013C77C 0013C7AC 0013C780 7C90F65C ntdll.dll!RtlNtStatusToDosError+0x2f 0013C784 7C90F661 ntdll.dll!RtlNtStatusToDosError+0x34 0013C788 0013C7F0 0013C78C 7C90D96E ntdll.dll!NtQueryValueKey 0013C790 0013C8B0 0013C794 0013C788 0013C798 7C90D97A ntdll.dll!NtQueryValueKey+0xc 0013C79C 0013DD50 0013C7A0 7C90E920 ntdll.dll!strchr+0x113 0013C7A4 7C90F668 ntdll.dll!RtlNtStatusToDosError+0x3b 0013C7A8 FFFFFFFF 0013C7AC 7C90F661 ntdll.dll!RtlNtStatusToDosError+0x34 0013C7B0 77DD6FEB ADVAPI32.dll!RegCloseKey+0x3c4 0013C7B4 00000000 0013C7B8 00000000 0013C7BC 0013CD60 0013C7C0 77DD6FF6 ADVAPI32.dll!RegCloseKey+0x3cf 0013C7C4 0013C8D4 0013C7C8 0000072C 0013C7CC 0013C8CC 0013C7D0 0013C8C4 0013C7D4 0000072C 0013C7D8 0013CD60 0013C7DC 0013C7F0 0013C7E0 00000022 0013C7E4 00000000 0013C7E8 00000000 0013C7EC 0013C7FC 0013C7F0 00000000 0013C7F4 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013C7F8 00176660 -> 11 00 10 00 0E 01 08 00 00 00 00 00 00 00 00 00 0013C7FC 0013C8C8 0013C800 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013C804 001609B8 -> 68 66 17 00 01 00 03 00 04 00 00 01 0A 00 00 00 0013C808 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013C80C 0017F67C -> 20 00 A4 00 98 D8 16 00 00 00 00 00 00 00 00 00 0013C810 0013C828 0013C814 7C91F934 ntdll.dll!RtlSplay+0x34 0013C818 77E46460 ADVAPI32.dll!ElfFlushEventLog+0xd60f 0013C81C 0013C86C 0013C820 0017F1B0 -> 00 00 04 00 01 01 00 00 18 00 1A 00 E8 F2 16 00 0013C824 0013C860 0013C828 0013C840 0013C82C 0013C840 0013C830 7C91FAAB ntdll.dll!RtlLookupElementGenericTable+0x54 0013C834 0017F198 -> 98 F1 17 00 80 F0 17 00 00 00 00 00 64 64 E4 77 0013C838 0013C8CC 0013C83C 0017F67C -> 20 00 A4 00 98 D8 16 00 00 00 00 00 00 00 00 00 0013C840 0013C858 0013C844 7C91FA6F ntdll.dll!RtlLookupElementGenericTable+0x18 0013C848 77E46460 ADVAPI32.dll!ElfFlushEventLog+0xd60f 0013C84C 0013C86C 0013C850 0013C860 0013C854 0013C864 0013C858 0013C8CC 0013C85C 77DD9153 ADVAPI32.dll!MD4Update+0x44f 0013C860 0017F198 -> 98 F1 17 00 80 F0 17 00 00 00 00 00 64 64 E4 77 0013C864 00000001 0013C868 00000000 0013C86C 00040000 0013C870 00000000 0013C874 00000000 0013C878 00000000 0013C87C 00000000 0013C880 00000000 0013C884 00000000 0013C888 00000000 0013C88C 00000000 0013C890 00000000 0013C894 00000000 0013C898 00000000 0013C89C 00000000 0013C8A0 00000000 0013C8A4 00000000 0013C8A8 00000000 0013C8AC 00000000 0013C8B0 00000000 0013C8B4 00000000 0013C8B8 00000000 0013C8BC 00000000 0013C8C0 00000000 0013C8C4 00000000 0013C8C8 00000000 0013C8CC 0013CFBC 0013C8D0 77E03A79 ADVAPI32.dll!AbortSystemShutdownW+0x661e 0013C8D4 77E46460 ADVAPI32.dll!ElfFlushEventLog+0xd60f 0013C8D8 00040000 0013C8DC 0013D098 0013C8E0 0013D0FC -> win.exe 0013C8E4 77DDA8E8 ADVAPI32.dll!IdentifyCodeAuthzLevelW+0xa20 0013C8E8 0013C888 0013C8EC 0013DD50 0013C8F0 7C90E920 ntdll.dll!strchr+0x113 0013C8F4 7C914E08 ntdll.dll!RtlConvertSidToUnicodeString+0x253 0013C8F8 0000005C 0013C8FC 0013CB74 0013C900 0013D01C 0013C904 00000016 0013C908 0013D018 0013C90C 0013D00C 0013C910 0013D020 0013C914 0017F640 -> A8 F5 17 00 00 00 00 00 00 00 00 00 84 63 17 00 0013C918 0017F5C0 -> FA D7 1C 19 40 F2 17 4A 89 86 94 D4 80 A6 C8 CA 0013C91C 00200020 0013C920 0013CD60 0013C924 00000000 0013C928 00000000 0013C92C 001766D8 -> *.exe 0013C930 00040000 0013C934 0000072C 0013C938 80000002 0013C93C 00000002 0013C940 02080020 0013C944 0013C950 -> C:\WINDOWS\*.exe 0013C948 00000000 0013C94C 00300039 -> 05 27 02 1C 05 28 02 1C 05 29 02 1C 05 2A 02 1C 0013C950 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013C954 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C958 004E0049 0013C95C 004F0044 0013C960 00530057 0013C964 002A005C -> 01 28 00 00 21 24 00 00 01 2C 00 00 A7 27 00 00 0013C968 0065002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C96C 00650078 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C970 00200000 0013C974 006E0049 -> istBox 0013C978 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013C97C 006E0072 -> SOFTWARE\Classes\Unmarshalers",4,"O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522 0013C980 0013C99C 0013C984 7C915199 ntdll.dll!bsearch+0x46 0013C988 0013C9C4 0013C98C 001400E4 -> 02 00 00 00 C8 10 00 00 2C 03 00 00 01 00 00 00 0013C990 00000004 0013C994 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013C998 00140000 -> Actx 0013C99C 0013C9DC 0013C9A0 7C91538B ntdll.dll!bsearch+0x238 0013C9A4 0013C9C4 0013C9A8 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013C9AC 00000000 0013C9B0 00000010 0013C9B4 00000000 0013C9B8 0013CA60 0013C9BC 001410C8 -> SsHd, 0013C9C0 F60E87FC 0013C9C4 0013CA14 0013C9C8 7C915721 ntdll.dll!RtlHashUnicodeString+0x164 0013C9CC 0013CDAC 0013C9D0 00000000 0013C9D4 00000001 0013C9D8 0013CA68 0013C9DC 001410C8 -> SsHd, 0013C9E0 C0150008 0013C9E4 00000000 0013C9E8 00000000 0013C9EC 00000002 0013C9F0 0013CA64 0013C9F4 C0150008 0013C9F8 00000000 0013C9FC 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013CA00 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013CA04 0013CA24 0013CA08 7C9156A2 ntdll.dll!RtlHashUnicodeString+0xe5 0013CA0C 0013CA48 0013CA10 0013CA80 -> @"& 0013CA14 0013CA6C 0013CA18 0013CA20 0013CA1C 001410C8 -> SsHd, 0013CA20 00000000 0013CA24 0013CA70 -> P"& 0013CA28 7C91554D ntdll.dll!RtlFindActivationContextSectionString+0xdc 0013CA2C 0013CA48 0013CA30 0013CA80 -> @"& 0013CA34 0013CA6C 0013CA38 0013CA64 0013CA3C 0013CDAC 0013CA40 0013D2C4 0013CA44 00000000 0013CA48 00000018 0013CA4C 00000000 0013CA50 00000000 0013CA54 00000002 0013CA58 00000003 0013CA5C 00000002 0013CA60 00000001 0013CA64 00000000 0013CA68 F60E87FC 0013CA6C 0013CDAC 0013CA70 00262250 -> F0 22 26 00 A8 21 26 00 F8 22 26 00 B0 21 26 00 0013CA74 0026228C -> 94 27 26 00 80 E2 97 7C CE 04 75 51 00 00 00 00 0013CA78 0013CD34 0013CA7C 7C915ED5 ntdll.dll!RtlValidateUnicodeString+0x10b 0013CA80 00262240 -> 00 00 00 00 00 00 00 00 0B 00 0A 00 8B 01 08 00 0013CA84 0013CDD4 0013CA88 7C915F0C ntdll.dll!RtlValidateUnicodeString+0x142 0013CA8C 00000216 0013CA90 0013D2C4 0013CA94 00000000 0013CA98 00000024 0013CA9C 008A005A 0013CAA0 001632BE -> S-1-5-21-1409082233-920026266-1708537768-1003 0013CAA4 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CAA8 0000072C 0013CAAC 0013CAB4 0013CAB0 00000000 0013CAB4 00000501 0013CAB8 7C97E280 ntdll.dll!NlsMbOemCodePageTag+0x1d8 0013CABC 00010015 0013CAC0 0013CAD0 0013CAC4 00000000 0013CAC8 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013CACC 00163298 -> 17 00 3A 00 91 01 0C 00 00 00 00 00 45 00 47 00 0013CAD0 0013CB9C 0013CAD4 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013CAD8 0013CDB8 -> P"& 0013CADC 00163B10 -> C8 3C 16 00 5C 00 50 00 72 00 6F 00 67 00 72 00 0013CAE0 0013CBF8 0013CAE4 00AC00F0 0013CAE8 00000000 0013CAEC 00AC010E 0013CAF0 00000000 0013CAF4 0013CE24 0013CAF8 00000000 0013CAFC 001632A0 -> 00 00 00 00 45 00 47 00 49 00 53 00 54 00 52 00 0013CB00 0100CD90 0013CB04 7C912E61 ntdll.dll!RtlValidSid+0x3f 0013CB08 0013CBF8 0013CB0C 0000001E 0013CB10 0013CB3C 0013CB14 7C914EE7 ntdll.dll!RtlAppendUnicodeToString+0x4d 0013CB18 001632A0 -> 00 00 00 00 45 00 47 00 49 00 53 00 54 00 52 00 0013CB1C 7C915076 -> \REGISTRY\USER\ 0013CB20 0000001E 0013CB24 00000000 0013CB28 00000000 0013CB2C 0013CBF8 0013CB30 0020001E 0013CB34 00002E58 0013CB38 0013CBC0 0013CB3C 000000B8 0013CB40 0013CB5C -> \WINDOWS\*.exe 0013CB44 0013CB74 0013CB48 00000000 0013CB4C 00000000 0013CB50 00000022 0013CB54 003F005C 0013CB58 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013CB5C 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CB60 004E0049 0013CB64 004F0044 0013CB68 00530057 0013CB6C 002A005C -> 01 28 00 00 21 24 00 00 01 2C 00 00 A7 27 00 00 0013CB70 0065002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CB74 00650078 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CB78 00200000 0013CB7C 006E0049 -> istBox 0013CB80 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CB84 006E0072 -> SOFTWARE\Classes\Unmarshalers",4,"O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522 0013CB88 00740065 0013CB8C 00460020 ManageACL_32.exe+0x60020 0013CB90 006C0069 -> 00 04 00 00 01 0C 00 E8 FF E9 B9 22 C0 22 C0 00 0013CB94 00730065 0013CB98 004F005C 0013CB9C 004B004C 0013CBA0 0000002A 0013CBA4 77DD0043 ADVAPI32.dll+0x43 0013CBA8 00000000 0013CBAC 00AC00F0 0013CBB0 00220020 0013CBB4 77DDB648 -> \CodeIdentifiers 0013CBB8 7C90D5DA ntdll.dll!NtOpenKey+0xc 0013CBBC 77DDB5A3 ADVAPI32.dll!CloseCodeAuthzLevel+0x60b 0013CBC0 0013CE58 0013CBC4 00020019 0013CBC8 0013CBD8 0013CBCC FFFFFFFF 0013CBD0 77E46460 ADVAPI32.dll!ElfFlushEventLog+0xd60f 0013CBD4 77DDB5CC ADVAPI32.dll!CloseCodeAuthzLevel+0x634 0013CBD8 00000018 0013CBDC 00000000 0013CBE0 0013CC04 0013CBE4 00000040 0013CBE8 00000000 0013CBEC 00000000 0013CBF0 0013CE58 0013CBF4 77DDB648 -> \CodeIdentifiers 0013CBF8 00000000 0013CBFC 00000000 0013CC00 02080096 0013CC04 020800EC 0013CC08 0013CC0C -> \REGISTRY\USER\S-1-5-21-1409082233-920026266-1708537768-10체 0013CC0C 0052005C 0013CC10 00470045 ManageACL_32.exe+0x70045 0013CC14 00530049 0013CC18 00520054 0013CC1C 005C0059 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC20 00530055 0013CC24 00520045 0013CC28 0053005C 0013CC2C 0031002D -> D0 02 02 CF D0 02 02 D0 D0 02 02 D1 D0 02 02 D2 0013CC30 0035002D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC34 0032002D -> 94 02 02 6F 94 02 02 70 94 02 02 71 94 02 02 72 0013CC38 002D0031 -> 02 0C 02 13 02 1C 02 22 02 29 02 30 02 38 02 3D 0013CC3C 00340031 -> 00 35 00 2E 00 6E 00 6C 00 73 00 00 00 00 00 00 0013CC40 00390030 -> 06 00 08 06 00 00 00 00 00 00 00 00 00 00 00 00 0013CC44 00380030 -> 09 00 00 00 48 02 0A 00 48 00 10 02 0B 00 48 00 0013CC48 00320032 -> 02 02 70 94 02 02 71 94 02 02 72 94 02 02 73 94 0013CC4C 00330033 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC50 0039002D -> EF FD 7F 06 00 08 06 00 00 00 00 00 00 00 00 00 0013CC54 00300032 -> 25 02 1C 05 26 02 1C 05 27 02 1C 05 28 02 1C 05 0013CC58 00320030 -> 6F 94 02 02 70 94 02 02 71 94 02 02 72 94 02 02 0013CC5C 00320036 -> 02 02 71 94 02 02 72 94 02 02 73 94 02 02 74 94 0013CC60 00360036 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC64 0031002D -> D0 02 02 CF D0 02 02 D0 D0 02 02 D1 D0 02 02 D2 0013CC68 00300037 -> 02 1C 05 27 02 1C 05 28 02 1C 05 29 02 1C 05 2A 0013CC6C 00350038 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC70 00370033 -> 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC74 00360037 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013CC78 002D0038 -> ȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013CC7C 00300031 -> 05 25 02 1C 05 26 02 1C 05 27 02 1C 05 28 02 1C 0013CC80 0013CCB4 0013CC84 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CC88 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013CC8C 0000000B 0013CC90 00160898 -> 98 04 17 00 01 00 BC 01 04 00 00 01 C0 01 00 00 0013CC94 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CC98 00170498 -> 00 00 00 00 80 65 E4 77 80 65 E4 77 00 00 00 00 0013CC9C 0013CC8C 0013CCA0 00690063 -> 00 00 00 00 00 06 00 0D 00 00 01 0D 00 6D 73 63 0013CCA4 0013CED0 0013CCA8 7C90E920 ntdll.dll!strchr+0x113 0013CCAC 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013CCB0 FFFFFFFF 0013CCB4 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013CCB8 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013CCBC 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013CCC0 00000000 0013CCC4 00000000 0013CCC8 0013CCE4 0013CCCC 7C915199 ntdll.dll!bsearch+0x46 0013CCD0 0013CD0C 0013CCD4 001400E4 -> 02 00 00 00 C8 10 00 00 2C 03 00 00 01 00 00 00 0013CCD8 00000004 0013CCDC 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013CCE0 00140000 -> Actx 0013CCE4 0013CD24 0013CCE8 7C91538B ntdll.dll!bsearch+0x238 0013CCEC 0013CD0C 0013CCF0 001400D4 -> 01 00 00 00 14 01 00 00 B4 0F 00 00 01 00 00 00 0013CCF4 00000000 0013CCF8 00000010 0013CCFC 00000000 0013CD00 0013CD34 0013CD04 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CD08 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013CD0C 0000002C 0013CD10 00160EC8 -> D8 FC 16 00 01 00 03 00 04 00 00 01 03 00 00 00 0013CD14 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CD18 0016FCD8 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013CD1C 0013CD0C 0013CD20 0013CDB0 0013CD24 0013CF50 0013CD28 7C90E920 ntdll.dll!strchr+0x113 0013CD2C 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013CD30 FFFFFFFF 0013CD34 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013CD38 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013CD3C 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013CD40 7C8855F8 kernel32.dll!SetConsoleMaximumWindowSize+0x5229 0013CD44 00000000 0013CD48 0013D0D0 -> C:\WINDOWS\system32\dwwin.exe 0013CD4C 7C916325 ntdll.dll!RtlValidateUnicodeString+0x55b 0013CD50 C0150008 0013CD54 00000000 0013CD58 00000000 0013CD5C 0013CDB4 0013CD60 0013CD68 0013CD64 001410C8 -> SsHd, 0013CD68 0013CDBC 0013CD6C 0013CDB8 -> P"& 0013CD70 7C91554D ntdll.dll!RtlFindActivationContextSectionString+0xdc 0013CD74 0013CD90 0013CD78 0013CDC8 0013CD7C 0013CDB4 0013CD80 0013CDAC 0013CD84 0013D2E4 0013CD88 0013CEE8 0013CD8C 0013D2C4 0013CD90 00000018 0013CD94 7FFDFC18 -> 00 00 65 00 64 00 00 00 61 00 62 00 6C 00 65 00 0013CD98 0013CDCC 0013CD9C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CDA0 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013CDA4 00000045 0013CDA8 00161378 -> 98 85 16 00 02 00 D9 01 04 00 00 01 DA 01 00 00 0013CDAC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CDB0 0017ABE0 -> 00 00 00 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013CDB4 0013CDA4 0013CDB8 00262250 -> F0 22 26 00 A8 21 26 00 F8 22 26 00 B0 21 26 00 0013CDBC 0013CFE8 0013CDC0 7C90E920 ntdll.dll!strchr+0x113 0013CDC4 7C910228 ntdll.dll!RtlAllocateHeap+0x164 0013CDC8 FFFFFFFF 0013CDCC 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013CDD0 7C91019B ntdll.dll!RtlAllocateHeap+0xd7 0013CDD4 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013CDD8 00000000 0013CDDC 0013D328 0013CDE0 0013D31C 0013CDE4 00000000 0013CDE8 00000000 0013CDEC 00000000 0013CDF0 00000000 0013CDF4 00000000 0013CDF8 00000000 0013CDFC 00000000 0013CE00 00000000 0013CE04 00000000 0013CE08 00000000 0013CE0C 00000000 0013CE10 00000000 0013CE14 00000000 0013CE18 00000000 0013CE1C 0013CEE8 0013CE20 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013CE24 00000000 0013CE28 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013CE2C 00170498 -> 00 00 00 00 80 65 E4 77 80 65 E4 77 00 00 00 00 0013CE30 00000000 0013CE34 00170498 -> 00 00 00 00 80 65 E4 77 80 65 E4 77 00 00 00 00 0013CE38 0013CEA8 0013CE3C 00000000 0013CE40 001A0018 0013CE44 7FFDFC00 -> advapi32.dll 0013CE48 00002E58 0013CE4C 00000000 0013CE50 7C91585F ntdll.dll!RtlHashUnicodeString+0x2a2 0013CE54 00020000 0013CE58 0013CE74 0013CE5C 0013CE74 0013CE60 0013CE74 0013CE64 00000002 0013CE68 00000002 0013CE6C 00000218 0013CE70 00000000 0013CE74 00000000 0013CE78 00002E58 0013CE7C 0013CFE4 0013CE80 0013CE90 0013CE84 00000000 0013CE88 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013CE8C 00163A38 -> 1A 00 3E 00 85 01 0A 00 00 00 00 00 5C 00 57 00 0013CE90 0013CF5C 0013CE94 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013CE98 00160B68 -> 40 3A 16 00 01 00 5C 00 04 00 00 01 5C 00 00 00 0013CE9C 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013CEA0 0016FE2A -> 00 00 8B 53 91 7C 22 00 2C 00 04 01 08 00 00 00 0013CEA4 00000000 0013CEA8 0013D0D0 -> C:\WINDOWS\system32\dwwin.exe 0013CEAC 0013D2C4 0013CEB0 0013D068 0013CEB4 00000000 0013CEB8 0013D070 0013CEBC 00000000 0013CEC0 0013D060 0013CEC4 00800000 0013CEC8 0013CF40 0013CECC 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013CED0 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013CED4 00000000 0013CED8 00000000 0013CEDC 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013CEE0 0013D2E0 0013CEE4 00020024 0013CEE8 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013CEEC 7C901000 ntdll.dll!RtlEnterCriticalSection 0013CEF0 00000000 0013CEF4 00010000 0013CEF8 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013CEFC 000000D0 0013CF00 7C914566 ntdll.dll!RtlQueryEnvironmentVariable_U+0x6d 0013CF04 7C910460 ntdll.dll!RtlReleasePebLock+0xf 0013CF08 7C980620 ntdll.dll!NlsMbOemCodePageTag+0x2578 0013CF0C 7C9145D9 ntdll.dll!RtlQueryEnvironmentVariable_U+0xe0 0013CF10 7C8855F8 kernel32.dll!SetConsoleMaximumWindowSize+0x5229 0013CF14 7C9144F9 ntdll.dll!RtlQueryEnvironmentVariable_U 0013CF18 0013D0D0 -> C:\WINDOWS\system32\dwwin.exe 0013CF1C 0013D4C0 0013CF20 00000108 0013CF24 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CF28 00000000 0013CF2C 00000000 0013CF30 0013CF40 0013CF34 00000000 0013CF38 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013CF3C 0016FCD0 -> 2C 00 41 00 58 01 0C 00 00 00 00 00 5C 00 57 00 0013CF40 0013D00C 0013CF44 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013CF48 00160EC8 -> D8 FC 16 00 01 00 03 00 04 00 00 01 03 00 00 00 0013CF4C 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013CF50 7FFDE000 -> 34 FF B7 00 00 00 B8 00 00 F0 B7 00 00 00 00 00 0013CF54 7C90DFAE ntdll.dll!NtWriteVirtualMemory 0013CF58 00001000 0013CF5C 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013CF60 7C80E49F kernel32.dll!DuplicateHandle+0x601 0013CF64 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CF68 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013CF6C 0013CFCC 0013CF70 0013D0A4 0013CF74 0013CF94 0013CF78 7C921C55 ntdll.dll!RtlCreateProcessParameters+0x3ca 0013CF7C 003D06B8 0013CF80 69451B5C -> Winsta0\Default 0013CF84 0000001E 0013CF88 0013D084 0013CF8C 00000208 0013CF90 00000000 0013CF94 0013CFF4 0013CF98 7C921BB6 ntdll.dll!RtlCreateProcessParameters+0x32b 0013CF9C 7C910460 ntdll.dll!RtlReleasePebLock+0xf 0013CFA0 7C980620 ntdll.dll!NlsMbOemCodePageTag+0x2578 0013CFA4 7C921885 ntdll.dll!RtlDeNormalizeProcessParams+0xa8 0013CFA8 7C921C00 ntdll.dll!RtlCreateProcessParameters+0x375 0013CFAC 00000160 0013CFB0 7C901295 ntdll.dll!RtlInitUnicodeString 0013CFB4 0013D078 0013CFB8 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013CFBC 0000003A 0013CFC0 00001000 0013CFC4 0000003C 0013CFC8 0000000E 0013CFCC 003D06DC 0013CFD0 00000000 0013CFD4 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013CFD8 00000000 0013CFDC 0013CFAC 0013CFE0 0013D0D0 -> C:\WINDOWS\system32\dwwin.exe 0013CFE4 0013D2F0 0013CFE8 7C90E920 ntdll.dll!strchr+0x113 0013CFEC 00011C10 0013CFF0 0000002C 0013CFF4 0013CF50 0013CFF8 7C90D39A ntdll.dll!NtFreeVirtualMemory+0xc 0013CFFC 7C9217D4 ntdll.dll!RtlDestroyProcessParameters+0x1e 0013D000 FFFFFFFF 0013D004 0013D01C 0013D008 0013D010 0013D00C 00008000 0013D010 00001000 0013D014 0013D300 0013D018 7C81B091 kernel32.dll!CreateProcessInternalW+0x11e9 0013D01C 003D0000 0013D020 7C81B054 kernel32.dll!CreateProcessInternalW+0x11ac 0013D024 0017A9C8 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D028 00000104 0013D02C 00000000 0013D030 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D034 00000000 0013D038 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D03C 00001100 0013D040 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D044 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D048 00000026 0013D04C 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D050 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D054 00000028 0013D058 00001000 0013D05C 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013D060 00011100 0013D064 7FFDE000 -> 34 FF B7 00 00 00 B8 00 00 F0 B7 00 00 00 00 00 0013D068 0016DCF8 -> 58 AF 17 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D06C 0017F6E0 -> 00 00 00 00 69 00 6D 00 45 00 6E 00 67 00 2E 00 0013D070 00010000 0013D074 00000000 0013D078 00280026 -> 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 0013D07C 0017A9C8 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D080 00000730 0013D084 00520050 0013D088 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013D08C 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013D090 0013D0D0 -> C:\WINDOWS\system32\dwwin.exe 0013D094 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013D098 0016DCF8 -> 58 AF 17 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D09C 00020000 0013D0A0 7C81183C kernel32.dll!DisableThreadLibraryCalls+0x2e 0013D0A4 0020001E 0013D0A8 69451B5C -> Winsta0\Default 0013D0AC 01540152 0013D0B0 0016FCD8 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D0B4 00000000 0013D0B8 00000000 0013D0BC 0013D0F8 -> dwwin.exe 0013D0C0 00030000 0013D0C4 00020000 0013D0C8 00001000 0013D0CC 003D0000 0013D0D0 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013D0D4 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013D0D8 004E0049 0013D0DC 004F0044 0013D0E0 00530057 0013D0E4 0073005C 0013D0E8 00730079 0013D0EC 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013D0F0 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013D0F4 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013D0F8 00770064 0013D0FC 00690077 -> trackbar32 0013D100 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013D104 00780065 0013D108 00000065 0013D10C 00000000 0013D110 00000000 0013D114 00000000 0013D118 00000000 0013D11C 00000000 0013D120 00000000 0013D124 00000000 0013D128 00000000 0013D12C 00000000 0013D130 00000000 0013D134 00000000 0013D138 00000000 0013D13C 00000000 0013D140 00000000 0013D144 00000000 0013D148 00000000 0013D14C 00000000 0013D150 00000000 0013D154 00000000 0013D158 00000000 0013D15C 00000000 0013D160 00000000 0013D164 00000000 0013D168 00000000 0013D16C 00000000 0013D170 00000000 0013D174 00000000 0013D178 00000000 0013D17C 00000000 0013D180 00000000 0013D184 00000000 0013D188 00000000 0013D18C 00000000 0013D190 00000000 0013D194 00000000 0013D198 00000000 0013D19C 00000000 0013D1A0 00000000 0013D1A4 00000000 0013D1A8 00000000 0013D1AC 00000000 0013D1B0 00000000 0013D1B4 00000000 0013D1B8 00000000 0013D1BC 00000000 0013D1C0 00000000 0013D1C4 00000000 0013D1C8 00000000 0013D1CC 00000000 0013D1D0 00000000 0013D1D4 00000000 0013D1D8 00000000 0013D1DC 00000000 0013D1E0 00000000 0013D1E4 00000000 0013D1E8 00000000 0013D1EC 00000000 0013D1F0 00000000 0013D1F4 00000000 0013D1F8 00000000 0013D1FC 00000000 0013D200 00000000 0013D204 00000000 0013D208 00000000 0013D20C 00000000 0013D210 00000000 0013D214 00000000 0013D218 00000000 0013D21C 00000000 0013D220 00000000 0013D224 00000000 0013D228 00000000 0013D22C 00000000 0013D230 00000000 0013D234 00000000 0013D238 00000000 0013D23C 00000000 0013D240 00000000 0013D244 00000000 0013D248 0013D258 0013D24C 00000000 0013D250 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013D254 0017F6D8 -> 32 00 14 00 19 01 0C 00 00 00 00 00 69 00 6D 00 0013D258 0013D324 0013D25C 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013D260 00160FE8 -> E0 F6 17 00 01 00 01 00 04 00 00 01 01 00 00 00 0013D264 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013D268 7C90CFEE ntdll.dll!NtClose 0013D26C 7C90FF2D ntdll.dll!RtlFreeHeap 0013D270 00000000 0013D274 00000000 0013D278 00000000 0013D27C 00000000 0013D280 00000000 0013D284 00000000 0013D288 00000000 0013D28C 00000000 0013D290 00000000 0013D294 00000000 0013D298 00000000 0013D29C 00000000 0013D2A0 00000000 0013D2A4 00000000 0013D2A8 00000000 0013D2AC 00000000 0013D2B0 00000000 0013D2B4 00000000 0013D2B8 00000000 0013D2BC 00000000 0013D2C0 00000000 0013D2C4 00000190 0013D2C8 00000000 0013D2CC 00000000 0013D2D0 00000000 0013D2D4 00000000 0013D2D8 00000000 0013D2DC 7C910323 ntdll.dll!RtlAllocateHeap+0x25f 0013D2E0 0017A9C8 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D2E4 00001000 0013D2E8 00000000 0013D2EC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013D2F0 7C90D6FA ntdll.dll!NtProtectVirtualMemory+0xc 0013D2F4 7C81045B kernel32.dll!SetEnvironmentVariableW+0x1cd 0013D2F8 00000730 0013D2FC 0013D320 0013D300 0013D31C 0013D304 0001DAEA 0013D308 00000032 0013D30C 0013D268 0013D310 0013D9C8 0013D314 0013DD50 0013D318 7C90E920 ntdll.dll!strchr+0x113 0013D31C 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013D320 FFFFFFFF 0013D324 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013D328 7C90CFEE ntdll.dll!NtClose 0013D32C 0013DD60 0013D330 7C81A94E kernel32.dll!CreateProcessInternalW+0xaa6 0013D334 0013D6A0 0013D338 7C81A75D kernel32.dll!CreateProcessInternalW+0x8b5 0013D33C 0013DEBC 0013D340 003B0000 -> 50 1C 00 00 50 0C 00 00 24 0C 00 00 50 4F 41 00 0013D344 7C90FE21 ntdll.dll!RtlGetLastWin32Error 0013D348 00000001 0013D34C 77B5A424 Apphelp.dll!SdbReadEntryInformation+0xbbf 0013D350 0013D340 0013D354 00000004 0013D358 0013D378 0013D35C 00000000 0013D360 7C800000 kernel32.dll+0x0 0013D364 0013D7BC 0013D368 00000002 0013D36C 00400128 ManageACL_32.exe+0x128 0013D370 00000000 0013D374 00000000 0013D378 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D37C 7C911A7D ntdll.dll!RtlInitializeCriticalSection+0x460 0013D380 7C800000 kernel32.dll+0x0 0013D384 00000001 0013D388 00000002 0013D38C 7C911AC1 ntdll.dll!RtlInitializeCriticalSection+0x4a4 0013D390 00000409 0013D394 7C800000 kernel32.dll+0x0 0013D398 7C800000 kernel32.dll+0x0 0013D39C 7C910323 ntdll.dll!RtlAllocateHeap+0x25f 0013D3A0 00065EE8 0013D3A4 7C800000 kernel32.dll+0x0 0013D3A8 7C800000 kernel32.dll+0x0 0013D3AC 7C8000F0 kernel32.dll+0xf0 0013D3B0 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D3B4 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D3B8 7C88A000 kernel32.dll!SetConsoleMaximumWindowSize+0x9c31 0013D3BC 00000409 0013D3C0 00000810 0013D3C4 00000000 0013D3C8 00000013 0013D3CC 7C90E920 ntdll.dll!strchr+0x113 0013D3D0 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D3D4 FFFFFFFF 0013D3D8 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D3DC 00000002 0013D3E0 77DD0000 ADVAPI32.dll+0x0 0013D3E4 7C88AF58 kernel32.dll!SetConsoleMaximumWindowSize+0xab89 0013D3E8 0013D44C 0013D3EC 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D3F0 00000041 0013D3F4 7C911A3F ntdll.dll!RtlInitializeCriticalSection+0x422 0013D3F8 7C911DB7 ntdll.dll!LdrFindResource_U+0x18 0013D3FC 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D400 0013D3DC 0013D404 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D408 00000000 0013D40C 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D410 0013D46C 0013D414 7C911DD5 ntdll.dll!LdrAccessResource+0x15 0013D418 00065EE8 0013D41C 7C88AF58 kernel32.dll!SetConsoleMaximumWindowSize+0xab89 0013D420 00000820 0013D424 00000000 0013D428 7C80A07E kernel32.dll!LoadResource+0x29 0013D42C 7C800000 kernel32.dll+0x0 0013D430 0013DAAC 0013D434 0013DAF4 0013D438 0013DB18 0013D43C 0013DA88 0013D440 0013DAD0 0013D444 00000041 0013D448 00000000 0013D44C 0013DE68 0013D450 00000001 0013D454 00000000 0013D458 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013D45C 00000000 0013D460 0017F6E0 -> 00 00 00 00 69 00 6D 00 45 00 6E 00 67 00 2E 00 0013D464 0017681A -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013D468 0013DA18 0013D46C 7C80A095 kernel32.dll!LoadResource+0x40 0013D470 0000017C 0013D474 7C830668 kernel32.dll!GetNumberFormatA+0x2ec 0013D478 00000002 0013D47C 00000000 0013D480 0017AB80 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013D484 00000000 0013D488 00000000 0013D48C 00000017 0013D490 00000000 0013D494 00000000 0013D498 00000000 0013D49C 0113D4B4 0013D4A0 0013DEAC 0013D4A4 00000000 0013D4A8 0017AB80 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013D4AC 00000000 0013D4B0 0017A9C8 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D4B4 00000000 0013D4B8 0000003C 0013D4BC 00000052 0013D4C0 00000044 0013D4C4 00000000 0013D4C8 69451B5C -> Winsta0\Default 0013D4CC 00000000 0013D4D0 00000000 0013D4D4 00000000 0013D4D8 00000000 0013D4DC 00000000 0013D4E0 00000000 0013D4E4 00000000 0013D4E8 00000000 0013D4EC 00000000 0013D4F0 00000000 0013D4F4 00000000 0013D4F8 00000000 0013D4FC 00000000 0013D500 00000000 0013D504 0013E318 -> C:\WINDOWS\system32 0013D508 0013D540 0013D50C 7C910020 ntdll.dll!RtlFreeHeap+0xf3 0013D510 0013DE02 -> -x -s 1852 0013D514 001766F0 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D518 7FFDE000 -> 34 FF B7 00 00 00 B8 00 00 F0 B7 00 00 00 00 00 0013D51C 00000000 0013D520 00000000 0013D524 00000000 0013D528 00000000 0013D52C 3000749A 0013D530 00000000 0013D534 00100000 0013D538 00001000 0013D53C 00000002 0013D540 00040000 0013D544 00000000 0013D548 0000010F 0013D54C 0001014C 0013D550 00000000 0013D554 0002C000 0013D558 00000000 0013D55C 00000004 0013D560 00000000 0013D564 00000000 0013D568 00168598 -> E0 AB 17 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013D56C 00000103 0013D570 7FFDE000 -> 34 FF B7 00 00 00 B8 00 00 F0 B7 00 00 00 00 00 0013D574 00000001 0013D578 00000008 0013D57C 000004E0 0013D580 00000C50 0013D584 0013DE02 -> -x -s 1852 0013D588 0016DCF8 -> 58 AF 17 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D58C 0113D848 0013D590 00000000 0013D594 00000018 0013D598 00000000 0013D59C 0013D6A8 0013D5A0 00000040 0013D5A4 00000000 0013D5A8 00000000 0013D5AC 00000000 0013D5B0 00000000 0013D5B4 00140000 -> Actx 0013D5B8 0013F000 0013D5BC 00040000 0013D5C0 00000005 0013D5C4 0101554D 0013D5C8 0013D5E4 0013D5CC 00000000 0013D5D0 00000000 0013D5D4 00000000 0013D5D8 00000000 0013D5DC 00000000 0013D5E0 00000000 0013D5E4 00000000 0013D5E8 00000000 0013D5EC 00140000 -> Actx 0013D5F0 0013D630 0013D5F4 7C91538B ntdll.dll!bsearch+0x238 0013D5F8 0013D618 0013D5FC 00000734 0013D600 00000730 0013D604 00000738 0013D608 30000000 0013D60C 00000000 0013D610 00000000 0013D614 006857D4 -> 5F 05 0E 5D 00 00 00 00 04 00 00 00 00 00 09 5D 0013D618 00000000 0013D61C 00000000 0013D620 00000000 0013D624 00000000 0013D628 00000000 0013D62C 00000000 0013D630 00000000 0013D634 00000000 0013D638 00000000 0013D63C 00000000 0013D640 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013D644 0016DCF8 -> 58 AF 17 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D648 00005ED5 0013D64C 00000000 0013D650 00000001 0013D654 00915F0C 0013D658 0013DAAC 0013D65C 0013DA88 0013D660 0013DAF4 0013D664 0013DAD0 0013D668 0013D698 0013D66C 0013D670 0013D670 021A0042 0013D674 00168598 -> E0 AB 17 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013D678 000004E0 0013D67C 00000A10 0013D680 0013D69C 0013D684 00000000 0013D688 0013D6C0 0013D68C 00000000 0013D690 0013D728 0013D694 00000000 0013D698 003C003A -> 00 00 00 00 00 00 80 00 3C 00 00 00 00 00 00 00 0013D69C 0016DCF8 -> 58 AF 17 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013D6A0 00000003 0013D6A4 00000000 0013D6A8 021A0042 0013D6AC 00168598 -> E0 AB 17 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013D6B0 00000002 0013D6B4 00000001 0013D6B8 00000000 0013D6BC 00000000 0013D6C0 0017A9DE -> system32 0013D6C4 00000001 0013D6C8 00000000 0013D6CC 00000184 0013D6D0 00000000 0013D6D4 0017F6E0 -> 00 00 00 00 69 00 6D 00 45 00 6E 00 67 00 2E 00 0013D6D8 00000000 0013D6DC 00000000 0013D6E0 00000000 0013D6E4 00000000 0013D6E8 00000734 0013D6EC 00000000 0013D6F0 00000738 0013D6F4 00000000 0013D6F8 00000200 0013D6FC 00010007 0013D700 00000000 0013D704 00000000 0013D708 00000000 0013D70C 00000000 0013D710 00000000 0013D714 00000000 0013D718 00000000 0013D71C 00000000 0013D720 00000000 0013D724 00000000 0013D728 00000000 0013D72C 020A0012 0013D730 00000000 0013D734 00000000 0013D738 0016E868 -> 68 E1 97 7C 98 F8 16 00 00 00 00 00 00 00 00 00 0013D73C 00000000 0013D740 00000000 0013D744 0013D7B4 0013D748 00000000 0013D74C 020A0012 0013D750 7FFDFC00 -> advapi32.dll 0013D754 00002E58 0013D758 00000000 0013D75C 7C91585F ntdll.dll!RtlHashUnicodeString+0x2a2 0013D760 00020000 0013D764 0013D780 0013D768 0013D780 0013D76C 0013D780 0013D770 00000002 0013D774 00000002 0013D778 7C910385 ntdll.dll!RtlImageDirectoryEntryToData+0x3f 0013D77C 7C900000 ntdll.dll+0x0 0013D780 00000000 0013D784 00002E58 0013D788 00000000 0013D78C 00000038 0013D790 00000020 0013D794 00000020 0013D798 0013D7DC 0013D79C 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013D7A0 7FFDE000 -> 34 FF B7 00 00 00 B8 00 00 F0 B7 00 00 00 00 00 0013D7A4 7C915BBD ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x2c2 0013D7A8 7C916E86 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x209 0013D7AC 3000749A 0013D7B0 00261FC0 -> ` & 0013D7B4 7C810735 kernel32.dll!CreateThread+0x2e 0013D7B8 00000018 0013D7BC 00003000 0013D7C0 0013FFFC 0013D7C4 00000020 0013D7C8 00000000 0013D7CC 0013D9D4 0013D7D0 00000000 0013D7D4 0013D84C 0013D7D8 00000000 0013D7DC 00000000 0013D7E0 00000000 0013D7E4 020A0012 0013D7E8 7FFDFC00 -> advapi32.dll 0013D7EC 00000000 0013D7F0 0000002A 0013D7F4 00000000 0013D7F8 00000000 0013D7FC 00000000 0013D800 00000000 0013D804 00000000 0013D808 00000000 0013D80C 00000000 0013D810 00000000 0013D814 00000000 0013D818 00000000 0013D81C 7C916F01 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x284 0013D820 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013D824 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D828 0013D908 0013D82C 7C916F0D ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x290 0013D830 0013D870 0013D834 7C90EADC ntdll.dll!strchr+0x2cf 0013D838 0013D8F8 0013D83C 7C90EA41 ntdll.dll!strchr+0x234 0013D840 FFFFFFFF 0013D844 0013D8F8 0013D848 0013D908 0013D84C 0013D884 0013D850 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013D854 00000000 0013D858 7C916E7F ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x202 0013D85C 0013D8F8 0013D860 7C916E86 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x209 0013D864 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013D868 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013D86C 00000000 0013D870 00000014 0013D874 00000001 0013D878 00000000 0013D87C 00000000 0013D880 00000010 0013D884 00000000 0013D888 00000000 0013D88C 000A0009 0013D890 7C881934 -> ntdll.dll 0013D894 00000000 0013D898 00000000 0013D89C 7C801000 kernel32.dll+0x1000 0013D8A0 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013D8A4 00000000 0013D8A8 00000000 0013D8AC 00000020 0013D8B0 00000020 0013D8B4 0013D904 0013D8B8 00000001 0013D8BC 0013D8E8 0013D8C0 7C918067 ntdll.dll!RtlAnsiCharToUnicodeChar+0x36 0013D8C4 0013D8E4 0013D8C8 00000002 0013D8CC 00000000 0013D8D0 0013DB73 0013D8D4 00000001 0013D8D8 0013DB73 0013D8DC 0013DB73 0013D8E0 FFFFFFFC 0013D8E4 00000032 0013D8E8 0013D8F8 0013D8EC 7C926018 ntdll.dll!RtlAllocateAndInitializeSid+0x185 0013D8F0 0013D900 0013D8F4 7C91AC42 ntdll.dll!RtlpUnWaitCriticalSection+0x10e3 0013D8F8 00000032 0013D8FC 0013DD90 0013D900 0013DD78 0013D904 7C91AAB7 ntdll.dll!RtlpUnWaitCriticalSection+0xf58 0013D908 00000032 0013D90C 00000104 0013D910 003B0000 -> 50 1C 00 00 50 0C 00 00 24 0C 00 00 50 4F 41 00 0013D914 7C91A484 ntdll.dll!RtlpUnWaitCriticalSection+0x925 0013D918 7C916E86 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x209 0013D91C 0013DC30 -> X+& 0013D920 00000001 0013D924 00000001 0013D928 00000007 0013D92C 00000000 0013D930 00000032 0013D934 00000000 0013D938 00000000 0013D93C 00000000 0013D940 00000000 0013D944 0013DD90 0013D948 77B402A5 -> NTDLL.DLL 0013D94C 00000000 0013D950 00000000 0013D954 694516BA faultrep.dll+0x16ba 0013D958 00000000 0013D95C 00000028 0013D960 0013DB70 0013D964 00000004 0013D968 FFFFFFFC 0013D96C 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013D970 00000010 0013D974 00000000 0013D978 00000038 0013D97C 00000000 0013D980 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013D984 00000000 0013D988 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013D98C 77B40290 Apphelp.dll+0x290 0013D990 00000000 0013D994 0013DA68 0013D998 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013D99C 00261F18 -> C0 1F 26 00 C0 1E 26 00 C8 1F 26 00 C8 1E 26 00 0013D9A0 00000000 0013D9A4 7FFDFBF8 -> 18 00 0A 02 00 FC FD 7F 61 00 64 00 76 00 61 00 0013D9A8 0013D91C 0013D9AC 00000734 0013D9B0 0013DCC8 0013D9B4 7C90E920 ntdll.dll!strchr+0x113 0013D9B8 7C916E90 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x213 0013D9BC FFFFFFFF 0013D9C0 7C916E86 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x209 0013D9C4 7C916E08 ntdll.dll!RtlMultiAppendUnicodeStringBuffer+0x18b 0013D9C8 00C400A8 0013D9CC 00000002 0013D9D0 00000C50 0013D9D4 00000C24 0013D9D8 00023E06 0013D9DC 00000000 0013D9E0 00000000 0013D9E4 00010000 0013D9E8 00000000 0013D9EC 00000000 0013D9F0 00000730 0013D9F4 0000072C 0013D9F8 000004E0 0013D9FC 00000A10 0013DA00 00000000 0013DA04 00000000 0013DA08 04000000 0013DA0C 00000000 0013DA10 00000000 0013DA14 0013DA4C 0013DA18 00000000 0013DA1C 00000000 0013DA20 00000000 0013DA24 00000000 0013DA28 00000000 0013DA2C 00000000 0013DA30 00000000 0013DA34 00000000 0013DA38 00000000 0013DA3C 00000000 0013DA40 00000000 0013DA44 00000000 0013DA48 00000000 0013DA4C 00000000 0013DA50 00000000 0013DA54 00000000 0013DA58 00000000 0013DA5C 00000000 0013DA60 00000000 0013DA64 00000000 0013DA68 00000000 0013DA6C 00000000 0013DA70 00000000 0013DA74 00000000 0013DA78 7FFDE000 -> 34 FF B7 00 00 00 B8 00 00 F0 B7 00 00 00 00 00 0013DA7C 00000000 0013DA80 77B50000 Apphelp.dll!SdbQueryDataEx+0x88f6 0013DA84 00176378 -> B8 64 17 00 48 F3 17 00 B0 F2 17 00 C4 64 17 00 0013DA88 00560000 -> C1 00 00 00 00 01 00 00 FF EE FF EE 09 00 00 00 0013DA8C 001767C4 -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013DA90 001767C4 -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013DA94 001767C4 -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013DA98 00000056 0013DA9C 00000056 0013DAA0 00000000 0013DAA4 00000000 0013DAA8 0013E520 -> P:\Temp\_shared\b5ba_appcompat.txt 0013DAAC 004E0000 0013DAB0 001766F0 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013DAB4 001766F0 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013DAB8 001766F0 -> 00 00 00 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013DABC 0000004E 0013DAC0 0000004E 0013DAC4 006C0065 -> 00 00 00 0D 00 04 00 00 01 0C 00 E8 FF E9 B9 22 0013DAC8 00320033 -> 02 70 94 02 02 71 94 02 02 72 94 02 02 73 94 02 0013DACC 0064002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DAD0 00520000 0013DAD4 0017681A -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013DAD8 0017681A -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013DADC 0017681A -> 00 00 3F 00 3F 00 5C 00 43 00 3A 00 5C 00 57 00 0013DAE0 00000052 0013DAE4 00000052 0013DAE8 0013DAF8 0013DAEC 00000000 0013DAF0 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013DAF4 004A0000 -> 00 00 00 00 00 00 00 00 00 00 01 00 48 1B DD B9 0013DAF8 0017673E -> 00 00 3A 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013DAFC 0017673E -> 00 00 3A 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013DB00 0017673E -> 00 00 3A 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013DB04 0000004A 0013DB08 0000004A 0013DB0C 00262F78 -> 9C 1E 26 00 D8 2E 26 00 A4 1E 26 00 E0 2E 26 00 0013DB10 00000000 0013DB14 00000000 0013DB18 003C0000 -> 40 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DB1C 00176788 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DB20 00176788 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DB24 00176788 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DB28 0000003C 0013DB2C 0000003C 0013DB30 00000000 0013DB34 00000000 0013DB38 00000000 0013DB3C 00000000 0013DB40 00000000 0013DB44 7C912221 ntdll.dll!LdrUnlockLoaderLock+0x58 0013DB48 7C912228 ntdll.dll!LdrUnlockLoaderLock+0x5f 0013DB4C 00000000 0013DB50 00000000 0013DB54 7C926A80 ntdll.dll!LdrUnloadAlternateResourceModule+0x47 0013DB58 00000000 0013DB5C 00000048 0013DB60 00000000 0013DB64 00000058 0013DB68 7C90E920 ntdll.dll!strchr+0x113 0013DB6C 7C912230 ntdll.dll!LdrUnlockLoaderLock+0x67 0013DB70 32353831 0013DB74 7C912228 ntdll.dll!LdrUnlockLoaderLock+0x5f 0013DB78 7C926A9B ntdll.dll!LdrUnloadAlternateResourceModule+0x62 0013DB7C 00000001 0013DB80 0C24009C 0013DB84 00260000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 10 00 00 0013DB88 0013DBDC 0013DB8C 00260000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 10 00 00 0013DB90 FFFFFFFF 0013DB94 0013DBDC 0013DB98 0013DBEC 0013DB9C 00010000 0013DBA0 00000009 0013DBA4 0001DB00 0013DBA8 0000000B 0013DBAC 0013DB08 0013DBB0 7C90E920 ntdll.dll!strchr+0x113 0013DBB4 0013DCC8 0013DBB8 7C90E920 ntdll.dll!strchr+0x113 0013DBBC 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013DBC0 FFFFFFFF 0013DBC4 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013DBC8 7C91D282 ntdll.dll!LdrDisableThreadCalloutsForDll+0xad0 0013DBCC 00260000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 10 00 00 0013DBD0 00000000 0013DBD4 00262F78 -> 9C 1E 26 00 D8 2E 26 00 A4 1E 26 00 E0 2E 26 00 0013DBD8 0013DBEC 0013DBDC 7C91D25C ntdll.dll!LdrDisableThreadCalloutsForDll+0xaaa 0013DBE0 00262F78 -> 9C 1E 26 00 D8 2E 26 00 A4 1E 26 00 E0 2E 26 00 0013DBE4 00262F78 -> 9C 1E 26 00 D8 2E 26 00 A4 1E 26 00 E0 2E 26 00 0013DBE8 77B41C09 Apphelp.dll+0x1c09 0013DBEC 7C91743E ntdll.dll!LdrUnloadDll+0x271 0013DBF0 7C97E174 ntdll.dll!NlsMbOemCodePageTag+0xcc 0013DBF4 7C91741C ntdll.dll!LdrUnloadDll+0x24f 0013DBF8 00000004 0013DBFC 0013DDA8 0013DC00 77B40000 Apphelp.dll+0x0 0013DC04 00000014 0013DC08 00000001 0013DC0C 00000000 0013DC10 00000000 0013DC14 00000010 0013DC18 7C97E230 ntdll.dll!NlsMbOemCodePageTag+0x188 0013DC1C 00000014 0013DC20 00000001 0013DC24 00000000 0013DC28 00000000 0013DC2C 00000010 0013DC30 00262B58 -> 88 2F 26 00 E8 2E 26 00 00 00 45 69 CD 3B 45 69 0013DC34 00262F88 -> AC 1E 26 00 58 2B 26 00 00 00 B4 77 09 1C B4 77 0013DC38 00262FB4 -> 80 E2 97 7C 94 27 26 00 D6 5B 50 47 00 00 00 00 0013DC3C 00000000 0013DC40 00000000 0013DC44 00000000 0013DC48 00000000 0013DC4C 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013DC50 00261EA4 -> C8 1E 26 00 80 2F 26 00 28 1F 26 00 88 2F 26 00 0013DC54 00000000 0013DC58 00262FB4 -> 80 E2 97 7C 94 27 26 00 D6 5B 50 47 00 00 00 00 0013DC5C 00000000 0013DC60 00000000 0013DC64 00262ED8 -> x/& 0013DC68 00262FB4 -> 80 E2 97 7C 94 27 26 00 D6 5B 50 47 00 00 00 00 0013DC6C 00261E9C -> C0 1E 26 00 78 2F 26 00 C8 1E 26 00 80 2F 26 00 0013DC70 7C97E280 ntdll.dll!NlsMbOemCodePageTag+0x1d8 0013DC74 0013DCAC 0013DC78 00262EE0 -> 80 2F 26 00 38 2E 26 00 58 2B 26 00 40 2E 26 00 0013DC7C 00262FB4 -> 80 E2 97 7C 94 27 26 00 D6 5B 50 47 00 00 00 00 0013DC80 00262F80 -> A4 1E 26 00 E0 2E 26 00 AC 1E 26 00 58 2B 26 00 0013DC84 7C97E230 ntdll.dll!NlsMbOemCodePageTag+0x188 0013DC88 00261EAC -> 28 1F 26 00 88 2F 26 00 00 00 00 00 0B 00 06 00 0013DC8C 7C97E230 ntdll.dll!NlsMbOemCodePageTag+0x188 0013DC90 00262794 -> B4 2F 26 00 8C 22 26 00 26 DD 10 56 00 00 00 00 0013DC94 77B41C09 Apphelp.dll+0x1c09 0013DC98 00000000 0013DC9C 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013DCA0 00000000 0013DCA4 00000000 0013DCA8 00000000 0013DCAC 00000000 0013DCB0 00262FB4 -> 80 E2 97 7C 94 27 26 00 D6 5B 50 47 00 00 00 00 0013DCB4 00262F78 -> 9C 1E 26 00 D8 2E 26 00 A4 1E 26 00 E0 2E 26 00 0013DCB8 0013DCAC 0013DCBC 00262F78 -> 9C 1E 26 00 D8 2E 26 00 A4 1E 26 00 E0 2E 26 00 0013DCC0 0013DBF8 0013DCC4 00000C0A 0013DCC8 0013DE38 0013DCCC 7C90E920 ntdll.dll!strchr+0x113 0013DCD0 7C917398 ntdll.dll!LdrUnloadDll+0x1cb 0013DCD4 FFFFFFFF 0013DCD8 7C91741C ntdll.dll!LdrUnloadDll+0x24f 0013DCDC 7C80AC97 kernel32.dll!FreeLibrary+0x19 0013DCE0 77B40000 Apphelp.dll+0x0 0013DCE4 0013DDA8 0013DCE8 00000000 0013DCEC 0000074C 0013DCF0 69459248 faultrep.dll!ReportFault+0x14ca 0013DCF4 77B40000 Apphelp.dll+0x0 0013DCF8 7C90DF4A ntdll.dll!NtWaitForMultipleObjects+0xc 0013DCFC 7C809590 kernel32.dll!CreateFileMappingA+0x86 0013DD00 00000002 0013DD04 0013DD20 0013DD08 00000001 0013DD0C 00000000 0013DD10 0013DD54 0013DD14 7C802530 kernel32.dll!WaitForSingleObject 0013DD18 003B0000 -> 50 1C 00 00 50 0C 00 00 24 0C 00 00 50 4F 41 00 0013DD1C 7C90FE21 ntdll.dll!RtlGetLastWin32Error 0013DD20 00000744 0013DD24 00000730 0013DD28 002E0067 -> 00 38 00 39 00 4F 00 51 00 63 00 6B 00 75 00 7F 0013DD2C 006F0063 -> 00 00 00 00 00 00 00 80 BF 00 00 00 00 80 8A 9A 0013DD30 005C006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DD34 00690057 -> 00 00 00 00 00 70 00 E7 B9 00 00 00 00 00 00 00 0013DD38 0064006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DD3C 00000000 0013DD40 00000014 0013DD44 00000001 0013DD48 00000000 0013DD4C 00000000 0013DD50 00000010 0013DD54 4D2FA200 0013DD58 FFFFFFFF 0013DD5C 7C90FE21 ntdll.dll!RtlGetLastWin32Error 0013DD60 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013DD64 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013DD68 00000000 0013DD6C 0013DD54 0013DD70 0013DD20 0013DD74 00000000 0013DD78 00000002 0013DD7C 0013DD14 0013DD80 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013DD84 0013E734 0013DD88 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013DD8C 7C809680 kernel32.dll!WaitForMultipleObjectsEx+0xa8 0013DD90 00000000 0013DD94 0013DDB0 0013DD98 7C80A115 kernel32.dll!WaitForMultipleObjects+0x18 0013DD9C 00000002 0013DDA0 0013DEC4 0013DDA4 00000000 0013DDA8 000493E0 0013DDAC 00000000 0013DDB0 0013E744 0013DDB4 6945763C faultrep.dll!ReportFaultDWM+0x14cf 0013DDB8 00000002 0013DDBC 0013DEC4 0013DDC0 00000000 0013DDC4 000493E0 0013DDC8 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013DDCC 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DDD0 004E0049 0013DDD4 004F0044 0013DDD8 00530057 0013DDDC 0073005C 0013DDE0 00730079 0013DDE4 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DDE8 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DDEC 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DDF0 00770064 0013DDF4 00690077 -> trackbar32 0013DDF8 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013DDFC 00780065 0013DE00 00200065 0013DE04 0078002D 0013DE08 002D0020 -> ʼnŋŐŕƊƌƚǨȇȌȓȜȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013DE0C 00200073 0013DE10 00380031 -> 00 00 00 48 02 0A 00 48 00 10 02 0B 00 48 00 10 0013DE14 00320035 -> 94 02 02 71 94 02 02 72 94 02 02 73 94 02 02 74 0013DE18 77B40000 Apphelp.dll+0x0 0013DE1C 77B5AA29 Apphelp.dll!SdbGrabMatchingInfo 0013DE20 0013DDA8 0013DE24 00000001 0013DE28 FFFFFFFF 0013DE2C 0013E318 -> C:\WINDOWS\system32 0013DE30 00000104 0013DE34 0013DE4C 0013DE38 7C8327F0 kernel32.dll!GetSystemDirectoryW+0x35 0013DE3C 0013E318 -> C:\WINDOWS\system32 0013DE40 7F6F2190 -> C:\WINDOWS\system32 0013DE44 00000026 0013DE48 003B0000 -> 50 1C 00 00 50 0C 00 00 24 0C 00 00 50 4F 41 00 0013DE4C 0013E744 0013DE50 0013E744 0013DE54 694574D7 faultrep.dll!ReportFaultDWM+0x136a 0013DE58 694574F3 faultrep.dll!ReportFaultDWM+0x1386 0013DE5C 00000001 0013DE60 0013F614 -> ManageACL_32.exe 0013DE64 00000000 0013DE68 00000044 0013DE6C 00000000 0013DE70 69451B5C -> Winsta0\Default 0013DE74 00000000 0013DE78 00000000 0013DE7C 00000000 0013DE80 00000000 0013DE84 00000000 0013DE88 00000000 0013DE8C 00000000 0013DE90 00000000 0013DE94 00000000 0013DE98 00000000 0013DE9C 00000000 0013DEA0 00000000 0013DEA4 00000000 0013DEA8 00000000 0013DEAC 00000730 0013DEB0 0000072C 0013DEB4 000004E0 0013DEB8 00000A10 0013DEBC 0013F490 -> watson.microsoft.com 0013DEC0 003BBA30 0013DEC4 00000744 0013DEC8 00000730 0013DECC 003B0000 -> 50 1C 00 00 50 0C 00 00 24 0C 00 00 50 4F 41 00 0013DED0 0000000C 0013DED4 00000000 0013DED8 00000001 0013DEDC 0013FA54 0013DEE0 0013DF08 -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013DEE4 00000013 0013DEE8 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013DEEC 00000740 0013DEF0 0000073C 0013DEF4 00000744 0013DEF8 00000001 0013DEFC 0000074C 0013DF00 00000748 0013DF04 00000000 0013DF08 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013DF0C 0050005C 0013DF10 006F0072 -> 9A E2 00 00 00 00 00 00 00 00 A0 45 ED B9 00 00 0013DF14 00720067 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF18 006D0061 -> 40 00 00 1A 61 C0 76 00 00 00 00 04 00 00 00 00 0013DF1C 00460020 ManageACL_32.exe+0x60020 0013DF20 006C0069 -> 00 04 00 00 01 0C 00 E8 FF E9 B9 22 C0 22 C0 00 0013DF24 00730065 0013DF28 0054005C 0013DF2C 00650077 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF30 006B0061 -> 00 00 00 00 00 00 00 00 00 00 00 48 00 E9 B9 00 0013DF34 006E0069 -> 00 69 00 6E 00 65 00 5C 00 53 00 4F 00 46 00 54 0013DF38 002E0067 -> 00 38 00 39 00 4F 00 51 00 63 00 6B 00 75 00 7F 0013DF3C 006F0063 -> 00 00 00 00 00 00 00 80 BF 00 00 00 00 80 8A 9A 0013DF40 005C006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF44 00690057 -> 00 00 00 00 00 70 00 E7 B9 00 00 00 00 00 00 00 0013DF48 0064006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF4C 0077006F 0013DF50 00200073 0013DF54 00650052 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF58 00610070 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF5C 00720069 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF60 00280020 -> 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 0013DF64 006C0041 -> 00 00 00 00 00 00 00 04 00 0D 00 00 01 0F 00 44 0013DF68 0020006C 0013DF6C 006E0069 -> 00 69 00 6E 00 65 00 5C 00 53 00 4F 00 46 00 54 0013DF70 004F0020 0013DF74 0065006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF78 005C0029 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF7C 00690066 -> 00 00 06 00 0D 00 00 01 0D 00 6D 73 63 74 6C 73 0013DF80 0065006C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF84 005C0073 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF88 0061004D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF8C 0061006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF90 00650067 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF94 00430041 ManageACL_32.exe+0x30041 0013DF98 005F004C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DF9C 00320033 -> 02 70 94 02 02 71 94 02 02 72 94 02 02 73 94 02 0013DFA0 0065002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DFA4 00650078 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013DFA8 00000000 0013DFAC 00000000 0013DFB0 00000000 0013DFB4 00000000 0013DFB8 00000000 0013DFBC 00000000 0013DFC0 00000000 0013DFC4 00000000 0013DFC8 00000000 0013DFCC 00000000 0013DFD0 00000000 0013DFD4 00000000 0013DFD8 0013DFE8 0013DFDC 0013DFDC 0013DFE0 0013DFDC 0013DFE4 00000200 0013DFE8 0013E058 0013DFEC 00000000 0013DFF0 00120010 0013DFF4 69451A84 -> d3d9.dll 0013DFF8 00002E58 0013DFFC 00000000 0013E000 7C91585F ntdll.dll!RtlHashUnicodeString+0x2a2 0013E004 00020000 0013E008 0013E024 0013E00C 0013E024 0013E010 0013E024 0013E014 00000002 0013E018 00000002 0013E01C 000004C0 0013E020 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013E024 00000000 0013E028 00002E58 0013E02C 0013E194 0013E030 0013E0CC 0013E034 0013E194 0013E038 7C915B58 ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x25d 0013E03C 0013E080 0013E040 00000000 0013E044 0013E270 0013E048 7C915BBD ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x2c2 0013E04C 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013E050 7C97E214 ntdll.dll!NlsMbOemCodePageTag+0x16c 0013E054 0016F2E8 -> Unrestricted 0013E058 00000000 0013E05C 0013E2C0 0013E060 0013E1D4 0013E064 00000000 0013E068 0013E234 0013E06C 00000000 0013E070 0013E1DC 0013E074 00800000 0013E078 0013E0F0 0013E07C 00000000 0013E080 00000000 0013E084 00000000 0013E088 00120010 0013E08C 69451A84 -> d3d9.dll 0013E090 00000000 0013E094 00000000 0013E098 00000000 0013E09C 00000000 0013E0A0 00000000 0013E0A4 00000000 0013E0A8 00000000 0013E0AC 00000000 0013E0B0 00000000 0013E0B4 00000000 0013E0B8 00000000 0013E0BC 00000000 0013E0C0 00000000 0013E0C4 00000000 0013E0C8 00000000 0013E0CC 00200000 0013E0D0 0013E170 0013E0D4 0013E170 0013E0D8 0013E170 0013E0DC 00000020 0013E0E0 00000020 0013E0E4 0016E430 -> 88 E8 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E0E8 0016FD80 -> stem32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0 0013E0EC 0016F8B0 -> 43 00 05 00 D4 01 0C 00 70 73 E7 77 30 DF 16 00 0013E0F0 0000000A 0013E0F4 00005600 0013E0F8 0013DD3C 0013E0FC 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013E100 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013E104 00000000 0013E108 00000000 0013E10C 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013E110 00770054 0013E114 00610065 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E118 0069006B -> 00 00 01 0D 00 6D 73 63 74 6C 73 5F 74 72 61 63 0013E11C 0067006E -> 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 0013E120 0063002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E124 006D006F -> 00 00 00 C0 76 00 00 00 00 80 8A 9A E2 00 00 00 0013E128 002D0020 -> ʼnŋŐŕƊƌƚǨȇȌȓȜȢȩȰȸȽɁɅɉɍɑɕɝɦɬɲɷɼʂʉʒʚʣʬʮʲʶʺʾ˃ˇˌː˔˘˜ˠˢӤ0456 0013E12C 004D0020 0013E130 006E0061 -> 00 6D 00 61 00 63 00 68 00 69 00 6E 00 65 00 5C 0013E134 00670061 -> 00 00 00 07 78 00 00 3C 00 00 00 00 05 00 00 00 0013E138 00410065 ManageACL_32.exe+0x10065 0013E13C 004C0043 0013E140 00000000 0013E144 00000000 0013E148 00000000 0013E14C 00000000 0013E150 00000000 0013E154 00000000 0013E158 00000000 0013E15C 00000000 0013E160 00000000 0013E164 00000000 0013E168 00000000 0013E16C 00000000 0013E170 00000000 0013E174 00000000 0013E178 00000000 0013E17C 00000000 0013E180 00000000 0013E184 00000000 0013E188 00000000 0013E18C 00000000 0013E190 00000000 0013E194 00000000 0013E198 00000000 0013E19C 00000000 0013E1A0 00000000 0013E1A4 00000000 0013E1A8 00000000 0013E1AC 00000000 0013E1B0 00000000 0013E1B4 00000000 0013E1B8 00000000 0013E1BC 00000000 0013E1C0 00000000 0013E1C4 00000000 0013E1C8 00000000 0013E1CC 00000000 0013E1D0 00000000 0013E1D4 00000000 0013E1D8 00000000 0013E1DC 00000000 0013E1E0 00000000 0013E1E4 00000000 0013E1E8 00000000 0013E1EC 00000000 0013E1F0 00000000 0013E1F4 00000000 0013E1F8 00000000 0013E1FC 00000000 0013E200 00000000 0013E204 00000000 0013E208 00000000 0013E20C 00000000 0013E210 00000000 0013E214 00000000 0013E218 00000000 0013E21C 00000000 0013E220 00000000 0013E224 00000000 0013E228 00000000 0013E22C 00000000 0013E230 00000000 0013E234 00000000 0013E238 00000000 0013E23C 00000000 0013E240 00000000 0013E244 00000000 0013E248 00000000 0013E24C 00000000 0013E250 00000000 0013E254 00000000 0013E258 00000000 0013E25C 00000000 0013E260 00000000 0013E264 00000000 0013E268 00000000 0013E26C 00000000 0013E270 00000000 0013E274 00000000 0013E278 00000000 0013E27C 00000000 0013E280 00000000 0013E284 00000000 0013E288 00000000 0013E28C 00000000 0013E290 00000000 0013E294 00000000 0013E298 00000000 0013E29C 00000000 0013E2A0 00000000 0013E2A4 00000000 0013E2A8 00000000 0013E2AC 00000000 0013E2B0 00000000 0013E2B4 00000000 0013E2B8 00000000 0013E2BC 00000000 0013E2C0 00000000 0013E2C4 00000000 0013E2C8 00000000 0013E2CC 00000000 0013E2D0 00000000 0013E2D4 00000000 0013E2D8 00000000 0013E2DC 00000000 0013E2E0 00000000 0013E2E4 00000000 0013E2E8 00000000 0013E2EC 00000000 0013E2F0 00000000 0013E2F4 00000000 0013E2F8 00000000 0013E2FC 00000000 0013E300 00000000 0013E304 00000000 0013E308 00000000 0013E30C 00000000 0013E310 00000000 0013E314 00000000 0013E318 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013E31C 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E320 004E0049 0013E324 004F0044 0013E328 00530057 0013E32C 0073005C 0013E330 00730079 0013E334 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E338 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E33C 00000032 0013E340 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013E344 00168590 -> 45 00 41 00 70 01 0E 00 E0 AB 17 00 3F 00 5C 00 0013E348 0013E414 0013E34C 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013E350 00161378 -> 98 85 16 00 02 00 D9 01 04 00 00 01 DA 01 00 00 0013E354 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013E358 0013E368 0013E35C 00000000 0013E360 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013E364 0016D940 -> 07 00 16 00 EA 01 0C 00 08 E3 16 00 00 00 00 00 0013E368 0013E434 0013E36C 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013E370 001607D8 -> 48 D9 16 00 04 00 38 00 04 00 00 01 41 00 00 00 0013E374 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013E378 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E37C 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E380 00000000 0013E384 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013E388 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013E38C 00160290 -> 90 02 16 00 90 02 16 00 98 02 16 00 98 02 16 00 0013E390 0016DF08 -> 00 00 00 00 18 E9 16 00 70 E9 16 00 78 D8 16 00 0013E394 00000000 0013E398 00000000 0013E39C 00010000 0013E3A0 0013E3B0 0013E3A4 00000000 0013E3A8 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013E3AC 0016DCF0 -> 42 00 43 00 5C 01 08 00 58 AF 17 00 5C 00 57 00 0013E3B0 0013E47C 0013E3B4 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013E3B8 001612E8 -> F8 DC 16 00 02 00 04 00 04 00 00 01 06 00 00 00 0013E3BC 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013E3C0 7C9020F5 ntdll.dll!memmove 0013E3C4 00000000 0013E3C8 0016D916 -> n\SystemRoot%*.exe 0013E3CC 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013E3D0 0016DF28 -> 57 00 05 00 27 01 0C 00 00 00 00 00 72 00 70 00 0013E3D4 00000038 0013E3D8 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E3DC 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013E3E0 0013E3D0 0013E3E4 0013E73C 0013E3E8 0013E42C 0013E3EC 7C90E920 ntdll.dll!strchr+0x113 0013E3F0 7C911468 ntdll.dll!RtlDeleteCriticalSection+0xee 0013E3F4 FFFFFFFF 0013E3F8 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013E3FC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013E400 7C9113F2 ntdll.dll!RtlDeleteCriticalSection+0x78 0013E404 0016D95C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E408 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E40C 00000000 0013E410 0016D878 -> 10 DF 16 00 50 D8 16 00 00 00 00 00 00 00 00 00 0013E414 0001E168 0013E418 00000007 0013E41C 00000210 0013E420 00000000 0013E424 0013E478 0013E428 7C90E920 ntdll.dll!strchr+0x113 0013E42C 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013E430 FFFFFFFF 0013E434 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013E438 7C80EF20 kernel32.dll!FindClose+0x84 0013E43C 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013E440 00000000 0013E444 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013E448 7C9020F5 ntdll.dll!memmove 0013E44C 0000005C 0013E450 0016D916 -> n\SystemRoot%*.exe 0013E454 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013E458 7C90D80A ntdll.dll!NtQueryInformationProcess+0xc 0013E45C 7C80AD05 kernel32.dll!SetErrorMode+0x56 0013E460 FFFFFFFF 0013E464 0000000C 0013E468 7C90DCAA ntdll.dll!NtSetInformationProcess+0xc 0013E46C 7C80ACE1 kernel32.dll!SetErrorMode+0x32 0013E470 FFFFFFFF 0013E474 0000000C 0013E478 0013E484 0013E47C 00000004 0013E480 00000000 0013E484 00000001 0013E488 0013E74C 0013E48C 7C81ECD1 kernel32.dll!GetLongPathNameW+0x2fa 0013E490 7C81ECE4 kernel32.dll!GetLongPathNameW+0x30d 0013E494 00000001 0013E498 00000103 0013E49C 00000000 0013E4A0 0013F59A -> Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013E4A4 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013E4A8 0016D948 -> 08 E3 16 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E4AC 0000005C 0013E4B0 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013E4B4 00000000 0013E4B8 0016D916 -> n\SystemRoot%*.exe 0013E4BC 0013F594 -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013E4C0 0013F594 -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\ManageACL_32.exe 0013E4C4 00000011 0013E4C8 0016D898 -> C:\WINDOWS\*.exe 0013E4CC 0016DCF8 -> 58 AF 17 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 0013E4D0 0016D916 -> n\SystemRoot%*.exe 0013E4D4 0013E50C -> files 0013E4D8 0016DD76 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E4DC 00000050 0013E4E0 00002810 0013E4E4 F500EA6D 0013E4E8 01CED735 0013E4EC A3DC5720 0013E4F0 01D2170F 0013E4F4 A3DC5720 0013E4F8 01D2170F 0013E4FC 00000000 0013E500 00000000 0013E504 769C212C USERENV.dll!Ordinal149+0x563 0013E508 76A6118C USERENV.dll+0xa118c 0013E50C 00690066 -> 00 00 06 00 0D 00 00 01 0D 00 6D 73 63 74 6C 73 0013E510 0065006C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E514 00000073 0013E518 0067006E -> 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 0013E51C 0063002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E520 003A0050 -> is program cannot be run in DOS mode.$ 0013E524 0054005C 0013E528 006D0065 -> 61 C0 76 00 00 00 00 04 00 00 00 00 00 C0 76 00 0013E52C 005C0070 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E530 0073005F 0013E534 00610068 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E538 00650072 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E53C 005C0064 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E540 00350062 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E544 00610062 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E548 0061005F -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E54C 00700070 -> 00 00 00 00 50 00 EE B9 00 00 00 00 0D 00 00 00 0013E550 006F0063 -> 00 00 00 00 00 00 00 80 BF 00 00 00 00 80 8A 9A 0013E554 0070006D -> 00 00 00 00 00 00 00 50 00 EE B9 00 00 00 00 0D 0013E558 00740061 0013E55C 0074002E 0013E560 00740078 0013E564 00000000 0013E568 00000000 0013E56C 00000000 0013E570 00000000 0013E574 00000000 0013E578 00000000 0013E57C 00000000 0013E580 00000000 0013E584 00000000 0013E588 00000000 0013E58C 00000000 0013E590 00000000 0013E594 00000000 0013E598 00000000 0013E59C 00000000 0013E5A0 00000000 0013E5A4 00000000 0013E5A8 00000000 0013E5AC 00000000 0013E5B0 00000000 0013E5B4 00000000 0013E5B8 00000000 0013E5BC 00000000 0013E5C0 00000000 0013E5C4 00000000 0013E5C8 00000000 0013E5CC 00000000 0013E5D0 00000000 0013E5D4 00000000 0013E5D8 00000000 0013E5DC 00000000 0013E5E0 00000000 0013E5E4 00000000 0013E5E8 00000000 0013E5EC 00000000 0013E5F0 00000000 0013E5F4 00000000 0013E5F8 00000000 0013E5FC 00000000 0013E600 00000000 0013E604 00000000 0013E608 00000000 0013E60C 00000000 0013E610 00000000 0013E614 00000000 0013E618 00000000 0013E61C 00000000 0013E620 00000000 0013E624 00000000 0013E628 00000000 0013E62C 00000000 0013E630 00000000 0013E634 00000000 0013E638 00000000 0013E63C 00000000 0013E640 00000000 0013E644 00000000 0013E648 00000000 0013E64C 00000000 0013E650 00000000 0013E654 00000000 0013E658 00000000 0013E65C 00000000 0013E660 00000000 0013E664 00000000 0013E668 00000000 0013E66C 00000000 0013E670 00000000 0013E674 00000000 0013E678 00000000 0013E67C 00000000 0013E680 00000000 0013E684 00000000 0013E688 00000000 0013E68C 00000000 0013E690 00000000 0013E694 00000000 0013E698 00000000 0013E69C 00000000 0013E6A0 00000000 0013E6A4 00000000 0013E6A8 00000000 0013E6AC 00000000 0013E6B0 00000000 0013E6B4 00000000 0013E6B8 00000000 0013E6BC 00000000 0013E6C0 00000000 0013E6C4 00000000 0013E6C8 00000000 0013E6CC 00000000 0013E6D0 00000000 0013E6D4 00000000 0013E6D8 00000000 0013E6DC 00000000 0013E6E0 00000000 0013E6E4 00000000 0013E6E8 00000000 0013E6EC 00000000 0013E6F0 00000000 0013E6F4 00000000 0013E6F8 00000000 0013E6FC 00000000 0013E700 00000000 0013E704 00000000 0013E708 00000000 0013E70C 00000000 0013E710 00000000 0013E714 00000000 0013E718 00000000 0013E71C 00000000 0013E720 00000000 0013E724 00000000 0013E728 0000FFE6 0013E72C 0013DDC8 -> C:\WINDOWS\system32\dwwin.exe -x -s 1852 0013E730 0013F614 -> ManageACL_32.exe 0013E734 0013F7A8 0013E738 6945EE90 faultrep.dll!ReportEREvent+0x525 0013E73C 69451B80 faultrep.dll+0x1b80 0013E740 FFFFFFFF 0013E744 0013F7B8 0013E748 694582B1 faultrep.dll!ReportFault+0x533 0013E74C 0013FA54 0013E750 FFFFFFFF 0013E754 00198312 0013E758 0013F490 -> watson.microsoft.com 0013E75C FFFFFFFF 0013E760 00000000 0013E764 7C90D96E ntdll.dll!NtQueryValueKey 0013E768 0016D001 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013E76C 00370178 -> 98 43 37 00 98 43 37 00 80 01 37 00 80 01 37 00 0013E770 00000000 0013E774 00000001 0013E778 00000000 0013E77C 00000000 0013E780 0013EA72 -> watson.microsoft.com 0013E784 00000001 0013E788 00000001 0013E78C 0013E774 0013E790 00000000 0013E794 00000000 0013E798 00000794 0013E79C 0000003A 0013E7A0 00000790 0013E7A4 00169B00 -> ncalrpc 0013E7A8 00169B18 -> IcaApi 0013E7AC 00000004 0013E7B0 00000000 0013E7B4 0013F490 -> watson.microsoft.com 0013E7B8 00000000 0013E7BC 0013F614 -> ManageACL_32.exe 0013E7C0 00000000 0013E7C4 0000077C 0013E7C8 0013FA54 0013E7CC 00374228 -> Software\Policies\Microsoft\Windows\System 0013E7D0 00000004 0013E7D4 00000000 0013E7D8 00000202 0013E7DC 00000001 0013E7E0 0016D870 -> 00 00 00 00 E0 E7 13 00 10 DF 16 00 50 D8 16 00 0013E7E4 FFFFFFFF 0013E7E8 00000000 0013E7EC 00000000 0013E7F0 00000000 0013E7F4 00000000 0013E7F8 00000000 0013E7FC 00000000 0013E800 00000000 0013E804 00000000 0013E808 00000000 0013E80C 00000000 0013E810 00000000 0013E814 00000778 0013E818 00000000 0013E81C 00000000 0013E820 00000000 0013E824 00000000 0013E828 00000000 0013E82C 00000000 0013E830 00000000 0013E834 00000774 0013E838 00000001 0013E83C 00000000 0013E840 00000000 0013E844 00000001 0013E848 00000001 0013E84C 00000001 0013E850 00000001 0013E854 00000000 0013E858 00000000 0013E85C 00000001 0013E860 00000001 0013E864 0000000A 0013E868 00000000 0013E86C 00000000 0013E870 00000000 0013E874 00000000 0013E878 00000000 0013E87C 00000000 0013E880 00000000 0013E884 00000000 0013E888 00000000 0013E88C 00000000 0013E890 00000000 0013E894 00000000 0013E898 00000000 0013E89C 00000000 0013E8A0 00000000 0013E8A4 00000000 0013E8A8 00000000 0013E8AC 00000000 0013E8B0 00000000 0013E8B4 00000000 0013E8B8 00000000 0013E8BC 00000000 0013E8C0 00000000 0013E8C4 00000000 0013E8C8 00000000 0013E8CC 00000000 0013E8D0 00000000 0013E8D4 00000000 0013E8D8 00000000 0013E8DC 00000000 0013E8E0 00000000 0013E8E4 00000000 0013E8E8 00000000 0013E8EC 00000000 0013E8F0 00000000 0013E8F4 00000000 0013E8F8 00000000 0013E8FC 00000000 0013E900 00000000 0013E904 00000000 0013E908 00000000 0013E90C 00000000 0013E910 00000000 0013E914 00000000 0013E918 00000000 0013E91C 00000000 0013E920 00000000 0013E924 00000000 0013E928 00000000 0013E92C 00000000 0013E930 00000000 0013E934 00000000 0013E938 00000000 0013E93C 00000000 0013E940 00000000 0013E944 00000000 0013E948 00000000 0013E94C 00000000 0013E950 00000000 0013E954 00000000 0013E958 00000000 0013E95C 00000000 0013E960 00000000 0013E964 00000000 0013E968 00000000 0013E96C 00000000 0013E970 00000000 0013E974 00000000 0013E978 00000000 0013E97C 00000000 0013E980 00000000 0013E984 00000000 0013E988 00000000 0013E98C 00000000 0013E990 00000000 0013E994 00000000 0013E998 00000000 0013E99C 00000000 0013E9A0 00000000 0013E9A4 00000000 0013E9A8 00000000 0013E9AC 00000000 0013E9B0 00000000 0013E9B4 00000000 0013E9B8 00000000 0013E9BC 00000000 0013E9C0 00000000 0013E9C4 00000000 0013E9C8 00000000 0013E9CC 00000000 0013E9D0 00000000 0013E9D4 00000000 0013E9D8 00000000 0013E9DC 00000000 0013E9E0 00000000 0013E9E4 00000000 0013E9E8 00000000 0013E9EC 00000000 0013E9F0 00000000 0013E9F4 00000000 0013E9F8 00000000 0013E9FC 00000000 0013EA00 00000000 0013EA04 00000000 0013EA08 00000000 0013EA0C 00000000 0013EA10 00000000 0013EA14 00000000 0013EA18 00000000 0013EA1C 00000000 0013EA20 00000000 0013EA24 00000000 0013EA28 00000000 0013EA2C 00000000 0013EA30 00000000 0013EA34 00000000 0013EA38 00000000 0013EA3C 00000000 0013EA40 00000000 0013EA44 00000000 0013EA48 00000000 0013EA4C 00000000 0013EA50 00000000 0013EA54 00000000 0013EA58 00000000 0013EA5C 00000000 0013EA60 00000000 0013EA64 00000000 0013EA68 00000000 0013EA6C 00000000 0013EA70 00770000 0013EA74 00740061 0013EA78 006F0073 -> E2 00 00 00 00 00 00 00 00 A0 45 ED B9 00 00 00 0013EA7C 002E006E -> Qcku‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013EA80 0069006D -> 01 0D 00 6D 73 63 74 6C 73 5F 74 72 61 63 6B 62 0013EA84 00720063 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013EA88 0073006F 0013EA8C 0066006F -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013EA90 002E0074 -> u‰’– ¢¤¦¨ª¬®³¸½ÁÅÊÑÖÛàåèíò÷üĀĄĉĐĕĚğĤħĬ8 0013EA94 006F0063 -> 00 00 00 00 00 00 00 80 BF 00 00 00 00 80 8A 9A 0013EA98 0000006D 0013EA9C 00000000 0013EAA0 00000000 0013EAA4 00000000 0013EAA8 00000000 0013EAAC 00000000 0013EAB0 00000000 0013EAB4 00000000 0013EAB8 00000000 0013EABC 00000000 0013EAC0 00000000 0013EAC4 00000000 0013EAC8 00000000 0013EACC 00000000 0013EAD0 00000000 0013EAD4 00000000 0013EAD8 00000000 0013EADC 00000000 0013EAE0 00000000 0013EAE4 00000000 0013EAE8 00000000 0013EAEC 00000000 0013EAF0 00000000 0013EAF4 00000000 0013EAF8 00000000 0013EAFC 00000000 0013EB00 00000000 0013EB04 00000000 0013EB08 00000000 0013EB0C 00000000 0013EB10 00000000 0013EB14 00000000 0013EB18 00000000 0013EB1C 00000000 0013EB20 00000000 0013EB24 00000000 0013EB28 00000000 0013EB2C 00000000 0013EB30 00000000 0013EB34 00000000 0013EB38 00000000 0013EB3C 00000000 0013EB40 00000000 0013EB44 00000000 0013EB48 00000000 0013EB4C 00000000 0013EB50 00000000 0013EB54 00000000 0013EB58 00000000 0013EB5C 00000000 0013EB60 00000000 0013EB64 00000000 0013EB68 00000000 0013EB6C 00000000 0013EB70 00000000 0013EB74 00000000 0013EB78 00000000 0013EB7C 00000000 0013EB80 00000000 0013EB84 00000000 0013EB88 00000000 0013EB8C 00000000 0013EB90 00000000 0013EB94 00000000 0013EB98 00000000 0013EB9C 00000000 0013EBA0 00000000 0013EBA4 00000000 0013EBA8 00000000 0013EBAC 00000000 0013EBB0 00000000 0013EBB4 00000000 0013EBB8 00000000 0013EBBC 00000000 0013EBC0 00000000 0013EBC4 00000000 0013EBC8 00000000 0013EBCC 00000000 0013EBD0 00000000 0013EBD4 00000000 0013EBD8 00000000 0013EBDC 00000000 0013EBE0 00000000 0013EBE4 00000000 0013EBE8 00000000 0013EBEC 00000000 0013EBF0 00000000 0013EBF4 00000000 0013EBF8 00000000 0013EBFC 00000000 0013EC00 00000000 0013EC04 00000000 0013EC08 00000000 0013EC0C 00000000 0013EC10 00000000 0013EC14 00000000 0013EC18 00000000 0013EC1C 00000000 0013EC20 00000000 0013EC24 00000000 0013EC28 00000000 0013EC2C 00000000 0013EC30 00000000 0013EC34 00000000 0013EC38 00000000 0013EC3C 00000000 0013EC40 00000000 0013EC44 00000000 0013EC48 00000000 0013EC4C 00000000 0013EC50 00000000 0013EC54 00000000 0013EC58 00000000 0013EC5C 00000000 0013EC60 00000000 0013EC64 00000000 0013EC68 00000000 0013EC6C 00000000 0013EC70 00000000 0013EC74 00000000 0013EC78 00000000 0013EC7C 00000000 0013EC80 00000000 0013EC84 00000000 0013EC88 00000000 0013EC8C 00000000 0013EC90 00000000 0013EC94 00000000 0013EC98 00000000 0013EC9C 00000000 0013ECA0 00000000 0013ECA4 00000000 0013ECA8 00000000 0013ECAC 00000000 0013ECB0 00000000 0013ECB4 00000000 0013ECB8 00000000 0013ECBC 00000000 0013ECC0 00000000 0013ECC4 00000000 0013ECC8 00000000 0013ECCC 00000000 0013ECD0 00000000 0013ECD4 00000000 0013ECD8 00000000 0013ECDC 00000000 0013ECE0 00000000 0013ECE4 00000000 0013ECE8 00000000 0013ECEC 00000000 0013ECF0 00000000 0013ECF4 00000000 0013ECF8 00000000 0013ECFC 00000000 0013ED00 00000000 0013ED04 00000000 0013ED08 00000000 0013ED0C 00000000 0013ED10 00000000 0013ED14 00000000 0013ED18 00000000 0013ED1C 00000000 0013ED20 00000000 0013ED24 00000000 0013ED28 00000000 0013ED2C 00000000 0013ED30 00000000 0013ED34 00000000 0013ED38 00000000 0013ED3C 00000000 0013ED40 00000000 0013ED44 00000000 0013ED48 00000000 0013ED4C 00000000 0013ED50 00000000 0013ED54 00000000 0013ED58 00000000 0013ED5C 00000000 0013ED60 00000000 0013ED64 00000000 0013ED68 00000000 0013ED6C 00000000 0013ED70 00000000 0013ED74 00000000 0013ED78 00000000 0013ED7C 00000000 0013ED80 00000000 0013ED84 00000000 0013ED88 00000000 0013ED8C 00000000 0013ED90 00000000 0013ED94 00000000 0013ED98 00000000 0013ED9C 00000000 0013EDA0 00000000 0013EDA4 00000000 0013EDA8 00000000 0013EDAC 00000000 0013EDB0 00000000 0013EDB4 00000000 0013EDB8 00000000 0013EDBC 00000000 0013EDC0 00000000 0013EDC4 00000000 0013EDC8 00000000 0013EDCC 00000000 0013EDD0 00000000 0013EDD4 00000000 0013EDD8 00000000 0013EDDC 00000000 0013EDE0 00000000 0013EDE4 00000000 0013EDE8 00000000 0013EDEC 00000000 0013EDF0 00000000 0013EDF4 00000000 0013EDF8 00000000 0013EDFC 00000000 0013EE00 00000000 0013EE04 00000000 0013EE08 00000000 0013EE0C 00000000 0013EE10 00000000 0013EE14 00000000 0013EE18 00000000 0013EE1C 00000000 0013EE20 00000000 0013EE24 00000000 0013EE28 00000000 0013EE2C 00000000 0013EE30 00000000 0013EE34 00000000 0013EE38 00000000 0013EE3C 00000000 0013EE40 00000000 0013EE44 00000000 0013EE48 00000000 0013EE4C 00000000 0013EE50 00000000 0013EE54 00000000 0013EE58 00000000 0013EE5C 00000000 0013EE60 00000000 0013EE64 00000000 0013EE68 00000000 0013EE6C 00000000 0013EE70 00000000 0013EE74 00000000 0013EE78 00000000 0013EE7C 00000000 0013EE80 00000000 0013EE84 00000000 0013EE88 00000000 0013EE8C 00000000 0013EE90 00000000 0013EE94 00000000 0013EE98 00000000 0013EE9C 00000000 0013EEA0 00000000 0013EEA4 00000000 0013EEA8 00000000 0013EEAC 00000000 0013EEB0 00000000 0013EEB4 00000000 0013EEB8 00000000 0013EEBC 00000000 0013EEC0 00000000 0013EEC4 00000000 0013EEC8 00000000 0013EECC 00000000 0013EED0 00000000 0013EED4 00000000 0013EED8 00000000 0013EEDC 00000000 0013EEE0 00000000 0013EEE4 00000000 0013EEE8 00000000 0013EEEC 00000000 0013EEF0 00000000 0013EEF4 00000000 0013EEF8 00000000 0013EEFC 00000000 0013EF00 00000000 0013EF04 00000000 0013EF08 00000000 0013EF0C 00000000 0013EF10 00000000 0013EF14 00000000 0013EF18 00000000 0013EF1C 00000000 0013EF20 00000000 0013EF24 00000000 0013EF28 00000000 0013EF2C 00000000 0013EF30 00000000 0013EF34 00000000 0013EF38 00000000 0013EF3C 00000000 0013EF40 00000000 0013EF44 00000000 0013EF48 00000000 0013EF4C 00000000 0013EF50 00000000 0013EF54 00000000 0013EF58 00000000 0013EF5C 00000000 0013EF60 00000000 0013EF64 00000000 0013EF68 00000000 0013EF6C 00000000 0013EF70 00000000 0013EF74 00000000 0013EF78 00000000 0013EF7C 00000000 0013EF80 00000000 0013EF84 00000000 0013EF88 00000000 0013EF8C 00000000 0013EF90 00000000 0013EF94 00000000 0013EF98 00000000 0013EF9C 00000000 0013EFA0 00000000 0013EFA4 00000000 0013EFA8 00000000 0013EFAC 00000000 0013EFB0 00000000 0013EFB4 00000000 0013EFB8 00000000 0013EFBC 00000000 0013EFC0 00000000 0013EFC4 00000000 0013EFC8 00000000 0013EFCC 00000000 0013EFD0 00000000 0013EFD4 00000000 0013EFD8 00000000 0013EFDC 00000000 0013EFE0 00000000 0013EFE4 00000000 0013EFE8 00000000 0013EFEC 00000000 0013EFF0 00000000 0013EFF4 00000000 0013EFF8 00000000 0013EFFC 00000000 0013F000 00000000 0013F004 00000000 0013F008 00000000 0013F00C 00000000 0013F010 00000000 0013F014 00000000 0013F018 00000000 0013F01C 00000000 0013F020 00000000 0013F024 00000000 0013F028 00000000 0013F02C 00000000 0013F030 00000000 0013F034 00000000 0013F038 00000000 0013F03C 00000000 0013F040 00000000 0013F044 00000000 0013F048 00000000 0013F04C 00000000 0013F050 00000000 0013F054 00000000 0013F058 00000000 0013F05C 00000000 0013F060 00000000 0013F064 00000000 0013F068 00000000 0013F06C 00000000 0013F070 00000000 0013F074 00000000 0013F078 00000000 0013F07C 00000000 0013F080 00000000 0013F084 00000000 0013F088 00000000 0013F08C 00000000 0013F090 00000000 0013F094 00000000 0013F098 00000000 0013F09C 00000000 0013F0A0 00000000 0013F0A4 00000000 0013F0A8 00000000 0013F0AC 00000000 0013F0B0 00000000 0013F0B4 00000000 0013F0B8 00000000 0013F0BC 00000000 0013F0C0 00000000 0013F0C4 00000000 0013F0C8 00000000 0013F0CC 00000000 0013F0D0 00000000 0013F0D4 00000000 0013F0D8 00000000 0013F0DC 00000000 0013F0E0 00000000 0013F0E4 00000000 0013F0E8 00000000 0013F0EC 00000000 0013F0F0 00000000 0013F0F4 00000000 0013F0F8 00000000 0013F0FC 00000000 0013F100 00000000 0013F104 00000000 0013F108 00000000 0013F10C 00000000 0013F110 00000000 0013F114 00000000 0013F118 00000000 0013F11C 00000000 0013F120 00000000 0013F124 00000000 0013F128 00000000 0013F12C 00000000 0013F130 00000000 0013F134 00000000 0013F138 00000000 0013F13C 00000000 0013F140 00000000 0013F144 00000000 0013F148 00000000 0013F14C 00000000 0013F150 00000000 0013F154 00000000 0013F158 00000000 0013F15C 00000000 0013F160 00000000 0013F164 00000000 0013F168 00000000 0013F16C 00000000 0013F170 00000000 0013F174 00000000 0013F178 00000000 0013F17C 00000000 0013F180 00000000 0013F184 00000000 0013F188 00000000 0013F18C 00000000 0013F190 00000000 0013F194 00000000 0013F198 00000000 0013F19C 00000000 0013F1A0 00000000 0013F1A4 00000000 0013F1A8 00000000 0013F1AC 00000000 0013F1B0 00000000 0013F1B4 00000000 0013F1B8 00000000 0013F1BC 00000000 0013F1C0 00000000 0013F1C4 00000000 0013F1C8 00000000 0013F1CC 00000000 0013F1D0 00000000 0013F1D4 00000000 0013F1D8 00000000 0013F1DC 00000000 0013F1E0 00000000 0013F1E4 00000000 0013F1E8 00000000 0013F1EC 00000000 0013F1F0 00000000 0013F1F4 00000000 0013F1F8 00000000 0013F1FC 00000000 0013F200 00000000 0013F204 00000000 0013F208 00000000 0013F20C 00000000 0013F210 00000000 0013F214 00000000 0013F218 00000000 0013F21C 00000000 0013F220 00000000 0013F224 00000000 0013F228 00000000 0013F22C 00000000 0013F230 00000000 0013F234 00000000 0013F238 00000000 0013F23C 00000000 0013F240 00000000 0013F244 00000000 0013F248 00000000 0013F24C 00000000 0013F250 00000000 0013F254 00000000 0013F258 00000000 0013F25C 00000000 0013F260 00000000 0013F264 00000000 0013F268 00000000 0013F26C 00000000 0013F270 00000000 0013F274 00000000 0013F278 00000000 0013F27C 00000000 0013F280 00000000 0013F284 00000001 0013F288 00000001 0013F28C 00000000 0013F290 0013F2E0 -> DOWS\system32\faultrep.dll 0013F294 00261EAC -> 28 1F 26 00 88 2F 26 00 00 00 00 00 0B 00 06 00 0013F298 0013F2C4 0013F29C 00000000 0013F2A0 0013F400 0013F2A4 0013F8C0 0013F2A8 00000018 0013F2AC 0013F950 0013F2B0 00000000 0013F2B4 0013F900 0013F2B8 00000000 0013F2BC 0013F94A 0013F2C0 00000000 0013F2C4 02160040 0013F2C8 0013F2D4 -> C:\WINDOWS\system32\faultrep.dll 0013F2CC 00000000 0013F2D0 00262B48 -> A0 2B 26 00 58 27 26 00 A8 2B 26 00 60 27 26 00 0013F2D4 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013F2D8 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F2DC 004E0049 0013F2E0 004F0044 0013F2E4 00530057 0013F2E8 0073005C 0013F2EC 00730079 0013F2F0 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F2F4 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F2F8 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F2FC 00610066 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F300 006C0075 -> C0 22 C0 00 00 00 00 68 42 87 8B 00 00 00 00 00 0013F304 00720074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F308 00700065 -> 00 82 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0013F30C 0064002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F310 006C006C -> 00 01 0C 00 E8 FF E9 B9 22 C0 22 C0 00 00 00 00 0013F314 00000000 0013F318 00000000 0013F31C 00000000 0013F320 00000000 0013F324 00000000 0013F328 00000000 0013F32C 00000000 0013F330 00000000 0013F334 0013F480 -> faultrep慷獴湯洮捩潲潳瑦挮浯 0013F338 00000000 0013F33C 00000000 0013F340 000D000C 0013F344 0013F7A0 0013F348 7C90E920 ntdll.dll!strchr+0x113 0013F34C 7C9167C8 ntdll.dll!RtlDosSearchPath_U+0xe9 0013F350 0013F3C0 0013F354 00000000 0013F358 01000040 0013F35C 0013F910 -> C:\WINDOWS\system32\faultrep.dll 0013F360 0013F3DC 0013F364 00000000 0013F368 0013F390 0013F36C 00020000 0013F370 0013F38C 0013F374 0013F38C 0013F378 0013F38C 0013F37C 00000002 0013F380 00000002 0013F384 00800040 0013F388 00310030 -> CF D0 02 02 D0 D0 02 02 D1 D0 02 02 D2 D0 02 02 0013F38C 00000000 0013F390 00002E58 0013F394 0013F4FC 0013F398 0013F434 0013F39C 0013F4FC 0013F3A0 7C915B58 ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x25d 0013F3A4 0013F3E8 0013F3A8 0013F588 0013F3AC 00000001 0013F3B0 7C915BBD ntdll.dll!RtlDosApplyFileIsolationRedirection_Ustr+0x2c2 0013F3B4 00470046 -> lid list format entry 0013F3B8 7C97E214 ntdll.dll!NlsMbOemCodePageTag+0x16c 0013F3BC 004B004A 0013F3C0 00000000 0013F3C4 0013F8C0 0013F3C8 0013F580 0013F3CC 00000000 0013F3D0 0013F588 0013F3D4 00000000 0013F3D8 0013F578 0013F3DC 00800040 0013F3E0 0013F458 -> C:\WINDOWS\system32\faultrep慷獴湯洮捩潲潳瑦挮浯 0013F3E4 00000000 0013F3E8 00000000 0013F3EC 00000000 0013F3F0 01000040 0013F3F4 0013F910 -> C:\WINDOWS\system32\faultrep.dll 0013F3F8 00000000 0013F3FC 004B004A 0013F400 00000000 0013F404 00000000 0013F408 00000000 0013F40C 00000000 0013F410 00000000 0013F414 00000000 0013F418 00000000 0013F41C 00000000 0013F420 00000000 0013F424 00000000 0013F428 00000000 0013F42C 00000000 0013F430 00000000 0013F434 00200000 0013F438 0013F4D8 0013F43C 0013F4D8 0013F440 0013F4D8 0013F444 00000020 0013F448 00000020 0013F44C 201C2019 0013F450 2022201D 0013F454 20142013 0013F458 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013F45C 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F460 004E0049 0013F464 004F0044 0013F468 00530057 0013F46C 0073005C 0013F470 00730079 0013F474 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F478 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F47C 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F480 00610066 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F484 006C0075 -> C0 22 C0 00 00 00 00 68 42 87 8B 00 00 00 00 00 0013F488 00720074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F48C 00700065 -> 00 82 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0013F490 73746177 0013F494 6D2E6E6F 0013F498 6F726369 0013F49C 74666F73 0013F4A0 6D6F632E 0013F4A4 00000000 0013F4A8 00000000 0013F4AC 00000000 0013F4B0 00000000 0013F4B4 00000000 0013F4B8 00000000 0013F4BC 00000000 0013F4C0 00000000 0013F4C4 00000000 0013F4C8 00000000 0013F4CC 00000000 0013F4D0 00000000 0013F4D4 00000000 0013F4D8 04290000 0013F4DC 7C91217E ntdll.dll!LdrLockLoaderLock+0x6b 0013F4E0 7C9121B4 ntdll.dll!LdrLockLoaderLock+0xa1 0013F4E4 7C912221 ntdll.dll!LdrUnlockLoaderLock+0x58 0013F4E8 7C912228 ntdll.dll!LdrUnlockLoaderLock+0x5f 0013F4EC 00000000 0013F4F0 00000000 0013F4F4 00000000 0013F4F8 0013F7A0 0013F4FC 0013F4EC 0013F500 7C916538 ntdll.dll!LdrLoadDll+0x20b 0013F504 0013F7A0 0013F508 7C90E920 ntdll.dll!strchr+0x113 0013F50C 7C912230 ntdll.dll!LdrUnlockLoaderLock+0x67 0013F510 FFFFFFFF 0013F514 7C912228 ntdll.dll!LdrUnlockLoaderLock+0x5f 0013F518 7C91659A ntdll.dll!LdrLoadDll+0x26d 0013F51C 00000001 0013F520 0C24000F 0013F524 7C916478 ntdll.dll!LdrLoadDll+0x14b 0013F528 00000000 0013F52C 7C90D96E ntdll.dll!NtQueryValueKey 0013F530 0016D001 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F534 000F000E 0013F538 00010020 0013F53C 00030002 0013F540 00050004 0013F544 00070006 0013F548 00090008 0013F54C 00000000 0013F550 000D000C 0013F554 0013F588 0013F558 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013F55C 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013F560 00000000 0013F564 00000000 0013F568 0013F900 0013F56C 00000000 0013F570 00000000 0013F574 0C24000F 0013F578 02080000 0013F57C 0013F58C 0013F580 00000000 0013F584 00000000 0013F588 0013F8C0 0013F58C 7C910000 ntdll.dll!RtlFreeHeap+0xd3 0013F590 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013F594 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013F598 0050005C 0013F59C 006F0072 -> 9A E2 00 00 00 00 00 00 00 00 A0 45 ED B9 00 00 0013F5A0 00720067 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5A4 006D0061 -> 40 00 00 1A 61 C0 76 00 00 00 00 04 00 00 00 00 0013F5A8 00460020 ManageACL_32.exe+0x60020 0013F5AC 006C0069 -> 00 04 00 00 01 0C 00 E8 FF E9 B9 22 C0 22 C0 00 0013F5B0 00730065 0013F5B4 0054005C 0013F5B8 00650077 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5BC 006B0061 -> 00 00 00 00 00 00 00 00 00 00 00 48 00 E9 B9 00 0013F5C0 006E0069 -> 00 69 00 6E 00 65 00 5C 00 53 00 4F 00 46 00 54 0013F5C4 002E0067 -> 00 38 00 39 00 4F 00 51 00 63 00 6B 00 75 00 7F 0013F5C8 006F0063 -> 00 00 00 00 00 00 00 80 BF 00 00 00 00 80 8A 9A 0013F5CC 005C006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5D0 00690057 -> 00 00 00 00 00 70 00 E7 B9 00 00 00 00 00 00 00 0013F5D4 0064006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5D8 0077006F 0013F5DC 00200073 0013F5E0 00650052 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5E4 00610070 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5E8 00720069 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F5EC 00280020 -> 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 0013F5F0 006C0041 -> 00 00 00 00 00 00 00 04 00 0D 00 00 01 0F 00 44 0013F5F4 0020006C 0013F5F8 006E0069 -> 00 69 00 6E 00 65 00 5C 00 53 00 4F 00 46 00 54 0013F5FC 004F0020 0013F600 0065006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F604 005C0029 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F608 00690066 -> 00 00 06 00 0D 00 00 01 0D 00 6D 73 63 74 6C 73 0013F60C 0065006C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F610 005C0073 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F614 0061004D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F618 0061006E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F61C 00650067 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F620 00430041 ManageACL_32.exe+0x30041 0013F624 005F004C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F628 00320033 -> 02 70 94 02 02 71 94 02 02 72 94 02 02 73 94 02 0013F62C 0065002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F630 00650078 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F634 007F0000 0013F638 04030402 0013F63C 0453201A 0013F640 2026201E 0013F644 20212020 0013F648 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013F64C 20390409 0013F650 040C040A 0013F654 040F040B 0013F658 00000002 0013F65C 201C2019 0013F660 2022201D 0013F664 20142013 0013F668 694629A8 faultrep.dll!ReportEREvent+0x403d 0013F66C 0013F73A -> ReportFault 0013F670 69462910 faultrep.dll!ReportEREvent+0x3fa5 0013F674 00000000 0013F678 0013F6C8 0013F67C 7C917D3B ntdll.dll!LdrGetProcedureAddress+0x4b 0013F680 0013F73A -> ReportFault 0013F684 0000000E 0013F688 69450000 faultrep.dll+0x0 0013F68C 69462970 faultrep.dll!ReportEREvent+0x4005 0013F690 694629A8 faultrep.dll!ReportEREvent+0x403d 0013F694 00000000 0013F698 00000001 0013F69C 0013F738 0013F6A0 00000000 0013F6A4 00000001 0013F6A8 69450000 faultrep.dll+0x0 0013F6AC 694500F0 faultrep.dll+0xf0 0013F6B0 0013F6A0 0013F6B4 00000001 0013F6B8 0013F6D8 0013F6BC 7C910385 ntdll.dll!RtlImageDirectoryEntryToData+0x3f 0013F6C0 69450000 faultrep.dll+0x0 0013F6C4 00000000 0013F6C8 0013F794 0013F6CC 7C917C02 ntdll.dll!RtlCompareUnicodeString+0x412 0013F6D0 69450000 faultrep.dll+0x0 0013F6D4 0013F73A -> ReportFault 0013F6D8 0013F734 -> ~}Ei 0013F6DC 0013F734 -> ~}Ei 0013F6E0 0013F73A -> ReportFault 0013F6E4 7C917CA7 ntdll.dll!RtlCompareUnicodeString+0x4b7 0013F6E8 7C97E174 ntdll.dll!NlsMbOemCodePageTag+0xcc 0013F6EC 7C917C51 ntdll.dll!RtlCompareUnicodeString+0x461 0013F6F0 00000000 0013F6F4 7C90D96E ntdll.dll!NtQueryValueKey 0013F6F8 0016D001 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F6FC 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013F700 00262B48 -> A0 2B 26 00 58 27 26 00 A8 2B 26 00 60 27 26 00 0013F704 00000208 0013F708 69462910 faultrep.dll!ReportEREvent+0x3fa5 0013F70C 0013F6FC 0013F710 00262B58 -> 88 2F 26 00 E8 2E 26 00 00 00 45 69 CD 3B 45 69 0013F714 0013F874 -> ~}Ei@ 0013F718 69450000 faultrep.dll+0x0 0013F71C 7C912230 ntdll.dll!LdrUnlockLoaderLock+0x67 0013F720 0013F738 0013F724 0013F738 0013F728 00000000 0013F72C 000001BC 0013F730 00262B48 -> A0 2B 26 00 58 27 26 00 A8 2B 26 00 60 27 26 00 0013F734 69457D7E faultrep.dll!ReportFault 0013F738 65520000 0013F73C 74726F70 0013F740 6C756146 0013F744 00260074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F748 0016D028 -> 00 00 00 00 01 00 00 00 34 00 00 00 64 00 72 00 0013F74C 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013F750 00000043 0013F754 FFFFFFFF 0013F758 00000000 0013F75C 000000A0 0013F760 0C24000D 0013F764 0013F738 0013F768 0013F780 0013F76C 0016D020 -> 43 00 04 04 C6 01 08 00 00 00 00 00 01 00 00 00 0013F770 00160168 -> 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 0013F774 00000000 0013F778 00002E58 0013F77C 0013F6F0 0013F780 7C9121B4 ntdll.dll!LdrLockLoaderLock+0xa1 0013F784 0013FA1C 0013F788 7C90E920 ntdll.dll!strchr+0x113 0013F78C 7C917C58 ntdll.dll!RtlCompareUnicodeString+0x468 0013F790 FFFFFFFF 0013F794 7C917C51 ntdll.dll!RtlCompareUnicodeString+0x461 0013F798 00007C51 0013F79C 0000FFE6 0013F7A0 0013E760 0013F7A4 7C917C51 ntdll.dll!RtlCompareUnicodeString+0x461 0013F7A8 0013FA1C 0013F7AC 6945EE90 faultrep.dll!ReportEREvent+0x525 0013F7B0 69451C48 faultrep.dll+0x1c48 0013F7B4 00000000 0013F7B8 0013FA2C 0013F7BC 7C86459E kernel32.dll!UnhandledExceptionFilter+0x55c 0013F7C0 0013FA54 0013F7C4 FFFFFFFF 0013F7C8 00000000 0013F7CC 00000000 0013F7D0 00000000 0013F7D4 0013F7F8 0013F7D8 7C912416 ntdll.dll!_strcmpi+0x102 0013F7DC 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013F7E0 0016B000 -> 04 04 02 00 C2 01 0E 00 08 D0 47 00 00 00 00 00 0013F7E4 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013F7E8 0016B000 -> 04 04 02 00 C2 01 0E 00 08 D0 47 00 00 00 00 00 0013F7EC 00160001 -> 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 00 0013F7F0 00160640 -> 08 00 C8 00 00 01 00 00 EE FF EE FF 00 00 00 00 0013F7F4 0013F820 0013F7F8 0013F82C 0013F7FC 7C918CD9 ntdll.dll!RtlReAllocateHeap+0x862 0013F800 00000200 0013F804 1016B000 0013F808 00000000 0013F80C 000000D6 0013F810 00000000 0013F814 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013F818 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013F81C 7C97E174 ntdll.dll!NlsMbOemCodePageTag+0xcc 0013F820 00160014 -> 00 FE 00 00 00 00 10 00 00 20 00 00 00 02 00 00 0013F824 7FFE0030 -> C:\WINDOWS 0013F828 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013F82C 0013FA5C 0013F830 7C911028 ntdll.dll!wcsncpy+0xaa9 0013F834 7C911086 ntdll.dll!wcsncpy+0xb07 0013F838 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013F83C 00169508 -> %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe 0013F840 000006A6 0013F844 00000005 0013F848 0013F868 0013F84C 0000012A 0013F850 7C804424 kernel32.dll!WaitForSingleObjectEx+0x1ed4 0013F854 0013F922 -> S\system32\faultrep.dll 0013F858 7C80262C kernel32.dll!WaitForSingleObjectEx+0xdc 0013F85C 000000E5 0013F860 0013F8B0 0013F864 7C917D3B ntdll.dll!LdrGetProcedureAddress+0x4b 0013F868 0013F922 -> S\system32\faultrep.dll 0013F86C 000003BA 0013F870 7C800000 kernel32.dll+0x0 0013F874 69457D7E faultrep.dll!ReportFault 0013F878 00000040 0013F87C 00000000 0013F880 00000001 0013F884 0013F920 -> WS\system32\faultrep.dll 0013F888 00000000 0013F88C 00120010 0013F890 7C81A984 -> Debugger 0013F894 00000018 0013F898 00000000 0013F89C 7C887378 kernel32.dll!SetConsoleMaximumWindowSize+0x6fa9 0013F8A0 00000040 0013F8A4 00000000 0013F8A8 00000000 0013F8AC FFFFFFFF 0013F8B0 0C24000E 0013F8B4 7C917C02 ntdll.dll!RtlCompareUnicodeString+0x412 0013F8B8 00000001 0013F8BC 0016D028 -> 00 00 00 00 01 00 00 00 34 00 00 00 64 00 72 00 0013F8C0 01000040 0013F8C4 0013F910 -> C:\WINDOWS\system32\faultrep.dll 0013F8C8 0013F922 -> S\system32\faultrep.dll 0013F8CC C000001D 0013F8D0 00414F50 ManageACL_32.exe+0x14f50 0013F8D4 0001003F 0013F8D8 00000000 0013F8DC 0013FA54 0013F8E0 0000FFFF 0013F8E4 00000004 0013F8E8 00000000 0013F8EC 00000000 0013F8F0 00000002 0013F8F4 0016D034 -> drwtsn32 -p %ld -e %ld -g 0013F8F8 000007C0 0013F8FC 0113F9CC 0013F900 69450000 faultrep.dll+0x0 0013F904 0013F9A4 0013F908 00000000 0013F90C 0113F920 0013F910 003A0043 -> 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 0013F914 0057005C -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F918 004E0049 0013F91C 004F0044 0013F920 00530057 0013F924 0073005C 0013F928 00730079 0013F92C 00650074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F930 0033006D -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F934 005C0032 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F938 00610066 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F93C 006C0075 -> C0 22 C0 00 00 00 00 68 42 87 8B 00 00 00 00 00 0013F940 00720074 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F944 00700065 -> 00 82 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0013F948 0064002E -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013F94C 006C006C -> 00 01 0C 00 E8 FF E9 B9 22 C0 22 C0 00 00 00 00 0013F950 00160000 -> C8 00 00 00 C2 01 00 00 FF EE FF EE 02 00 00 00 0013F954 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013F958 0000FFFF 0013F95C 00465C60 ManageACL_32.exe+0x65c60 0013F960 004647AC -> FlsGetValue 0013F964 0013F994 0013F968 7C90F65C ntdll.dll!RtlNtStatusToDosError+0x2f 0013F96C 7C90F661 ntdll.dll!RtlNtStatusToDosError+0x34 0013F970 004647AC -> FlsGetValue 0013F974 00465C60 ManageACL_32.exe+0x65c60 0013F978 0000FFFF 0013F97C 0013F970 0013F980 7C917D08 ntdll.dll!LdrGetProcedureAddress+0x18 0013F984 0013FA74 0013F988 7C90E920 ntdll.dll!strchr+0x113 0013F98C 004647AC -> FlsGetValue 0013F990 0000007F 0013F994 0013F9A4 0013F998 7C809430 kernel32.dll!GetTickCount+0xe6 0013F99C 0000007F 0013F9A0 00465C60 ManageACL_32.exe+0x65c60 0013F9A4 0013F9C0 0013F9A8 7C81F614 kernel32.dll!OpenEventA+0xd6 0013F9AC C0000139 0013F9B0 FFFFFFFF 0013F9B4 00482C18 ManageACL_32.exe+0x82c18 0013F9B8 00000000 0013F9BC 00000000 0013F9C0 00000000 0013F9C4 0013F9E4 0013F9C8 00437CF3 ManageACL_32.exe+0x37cf3 0013F9CC 00000005 0013F9D0 0013F9E4 0013F9D4 7C910323 ntdll.dll!RtlAllocateHeap+0x25f 0013F9D8 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013F9DC 7C800000 kernel32.dll+0x0 0013F9E0 7C800000 kernel32.dll+0x0 0013F9E4 7C8000F0 kernel32.dll+0xf0 0013F9E8 0013F9D8 0013F9EC 7C90D98A ntdll.dll!NtQueryVirtualMemory+0xc 0013F9F0 7C880BC5 kernel32.dll!SetConsoleMaximumWindowSize+0x7f6 0013F9F4 FFFFFFFF 0013F9F8 7C817778 kernel32.dll!RegisterWaitForInputIdle+0x52 0013F9FC 00000000 0013FA00 0013FA18 0013FA04 0000001C 0013FA08 0000000F 0013FA0C 7C817778 kernel32.dll!RegisterWaitForInputIdle+0x52 0013FA10 00003194 0013FA14 0013F7C8 0013FA18 7C817000 kernel32.dll!BaseCheckAppcompatCache+0x91 0013FA1C 0013FA74 0013FA20 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013FA24 7C864B20 kernel32.dll!UnhandledExceptionFilter+0xade 0013FA28 00000000 0013FA2C 0013FFF0 0013FA30 7C84396A kernel32.dll!ValidateLocale+0xa16a 0013FA34 0013FA54 0013FA38 7C839B11 kernel32.dll!ValidateLocale+0x311 0013FA3C 0013FA5C 0013FA40 00000000 0013FA44 0013FA5C 0013FA48 00000000 0013FA4C 00000000 0013FA50 00000000 0013FA54 0013FB48 0013FA58 0013FB5C 0013FA5C 0013FA80 0013FA60 7C9032A8 ntdll.dll!RtlConvertUlongToLargeInteger+0x6a 0013FA64 0013FB48 0013FA68 0013FFE0 0013FA6C 0013FB5C 0013FA70 0013FB1C 0013FA74 0013FE60 0013FA78 7C9032BC ntdll.dll!RtlConvertUlongToLargeInteger+0x7e 0013FA7C 0013FFE0 0013FA80 0013FB30 0013FA84 7C90327A ntdll.dll!RtlConvertUlongToLargeInteger+0x3c 0013FA88 0013FB48 0013FA8C 0013FFE0 0013FA90 0013FB5C 0013FA94 0013FB1C 0013FA98 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013FA9C 00000001 0013FAA0 0013FB48 0013FAA4 0013FFE0 0013FAA8 7C92A8C3 ntdll.dll!wcstol+0x13c 0013FAAC 0013FB48 0013FAB0 0013FFE0 0013FAB4 0013FB5C 0013FAB8 0013FB1C 0013FABC 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013FAC0 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FAC4 0013FB48 0013FAC8 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FACC 00435C24 ManageACL_32.exe+0x35c24 0013FAD0 7C9101DB ntdll.dll!RtlAllocateHeap+0x117 0013FAD4 00000000 0013FAD8 00169418 -> F0 75 46 00 01 00 00 00 00 00 00 00 02 00 00 00 0013FADC 00000001 0013FAE0 00000001 0013FAE4 00169498 -> 00 00 00 00 00 00 00 00 98 D7 47 00 00 00 00 00 0013FAE8 00130000 0013FAEC 00000000 0013FAF0 00000000 0013FAF4 001A0018 0013FAF8 00461CB4 -> kernel32.dll 0013FAFC 02080000 0013FB00 0013FD20 0013FB04 02080000 0013FB08 0013FB3C 0013FB0C 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013FB10 7C910222 ntdll.dll!RtlAllocateHeap+0x15e 0013FB14 00169738 -> 04 28 46 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FB18 00160178 -> 78 68 17 00 F0 04 17 00 80 01 16 00 80 01 16 00 0013FB1C 0016B000 -> 04 04 02 00 C2 01 0E 00 08 D0 47 00 00 00 00 00 0013FB20 00000000 0013FB24 00140000 -> Actx 0013FB28 0013D000 0013FB2C 00169BF0 -> 1E 00 02 00 BC 01 0C 00 E8 9C 16 00 58 9D 16 00 0013FB30 0013FE40 0013FB34 7C90E48A ntdll.dll!KiUserExceptionDispatcher+0xe 0013FB38 00000000 0013FB3C 0013FB5C 0013FB40 0013FB48 0013FB44 0013FB5C 0013FB48 C000001D 0013FB4C 00000000 0013FB50 00000000 0013FB54 00414F50 ManageACL_32.exe+0x14f50 0013FB58 00000000 0013FB5C 0001003F 0013FB60 00000000 0013FB64 00000000 0013FB68 00000000 0013FB6C 00000000 0013FB70 00000000 0013FB74 00000000 0013FB78 FFFF027F 0013FB7C FFFF0000 0013FB80 FFFFFFFF 0013FB84 734903A9 0013FB88 035D001B 0013FB8C 0013EFF8 0013FB90 FFFF0023 0013FB94 0033005F -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FB98 002E0032 -> 35 00 37 00 32 00 00 00 01 00 01 00 1F 02 0D 00 0013FB9C 00000065 0013FBA0 D80A0000 0013FBA4 B4117C90 0013FBA8 00000017 0013FBAC 0013F248 0013FBB0 00010024 0013FBB4 4A300000 0013FBB8 B4610016 0013FBBC 03030000 0013FBC0 03030303 0013FBC4 00000000 0013FBC8 03000300 0013FBCC 00030303 0013FBD0 0013F6D4 0013FBD4 00000000 0013FBD8 00000000 0013FBDC 00000000 0013FBE0 00000000 0013FBE4 00000000 0013FBE8 00000000 0013FBEC 0000003B 0013FBF0 00000023 0013FBF4 00000023 0013FBF8 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FBFC 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FC00 0013FEC0 0013FC04 0013FF3C -> `FF 0013FC08 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FC0C 00169A24 -> 50 03 16 00 5C 00 54 00 65 00 6D 00 05 00 03 00 0013FC10 0013FE40 0013FC14 00414F50 ManageACL_32.exe+0x14f50 0013FC18 0000001B 0013FC1C 00010286 0013FC20 0013FE28 0013FC24 00000023 0013FC28 0000027F 0013FC2C 002E0000 -> 29 06 00 00 30 06 48 06 A0 00 27 06 44 06 2D 06 0013FC30 00000000 0013FC34 00000000 0013FC38 00000000 0013FC3C 00000000 0013FC40 00001F80 0013FC44 004C0043 0013FC48 0033005F -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FC4C 002E0032 -> 35 00 37 00 32 00 00 00 01 00 01 00 1F 02 0D 00 0013FC50 00000065 0013FC54 00000000 0013FC58 00000000 0013FC5C 7C90D80A ntdll.dll!NtQueryInformationProcess+0xc 0013FC60 0000B411 0013FC64 00000000 0013FC68 00000017 0013FC6C 0013F248 0013FC70 00000024 0013FC74 00000000 0013FC78 00000001 0013FC7C 00164A30 -> 40 4C 16 00 08 4A 16 00 00 00 00 00 00 00 00 00 0013FC80 0000B461 0013FC84 00000000 0013FC88 03030000 0013FC8C 03030303 0013FC90 00000000 0013FC94 00000000 0013FC98 03000000 0013FC9C 03030300 0013FCA0 00000003 0013FCA4 00000000 0013FCA8 0013F6D4 0013FCAC 00000000 0013FCB0 00000000 0013FCB4 00000000 0013FCB8 00000000 0013FCBC 00000000 0013FCC0 00000000 0013FCC4 00000000 0013FCC8 00000000 0013FCCC 00000000 0013FCD0 00000000 0013FCD4 00000000 0013FCD8 00000000 0013FCDC 00000000 0013FCE0 00000043 0013FCE4 00000000 0013FCE8 00000000 0013FCEC 7C9115F9 ntdll.dll!RtlLogStackBackTrace+0x25 0013FCF0 0013F2C4 0013FCF4 00000000 0013FCF8 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013FCFC 00163FA0 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FD00 0013F390 0013FD04 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013FD08 00150778 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FD0C 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013FD10 00163FC8 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FD14 00163FA8 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FD18 00153A3C 0013FD1C 00000000 0013FD20 00000000 0013FD24 00000000 0013FD28 0013F2FC -> faultrep.dll 0013FD2C 00000000 0013FD30 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013FD34 00152098 0013FD38 0013F3C8 0013FD3C 7C910435 ntdll.dll!RtlAcquirePebLock+0x28 0013FD40 7C91043E ntdll.dll!RtlAcquirePebLock+0x31 0013FD44 0013F67C 0013FD48 00020024 0013FD4C 0013F44C -> ’“”•–—C:\WINDOWS\system32\faultrep慷獴湯洮捩潲潳瑦挮浯 0013FD50 00000005 0013FD54 7C9142B9 ntdll.dll!RtlDosPathNameToNtPathName_U+0x94 0013FD58 7FFD8000 0013FD5C 00000002 0013FD60 0013F338 0013FD64 7C926620 ntdll.dll!RtlDosSearchPath_Ustr+0x1ed 0013FD68 0013F33C 0013FD6C 00000000 0013FD70 7C9100B8 ntdll.dll!RtlFreeHeap+0x18b 0013FD74 00153A20 0013FD78 0013F408 0013FD7C 7C910041 ntdll.dll!RtlFreeHeap+0x114 0013FD80 001507D8 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FD84 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013FD88 00153A3C 0013FD8C 00153A28 0013FD90 00000000 0013FD94 00150000 -> Actx 0013FD98 00163FA8 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FD9C 0013F2B4 0013FDA0 00000000 0013FDA4 0013F472 -> stem32\faultrep慷獴湯洮捩潲潳瑦挮浯 0013FDA8 00000005 0013FDAC 000100A4 0013FDB0 00000005 0013FDB4 0013F2D4 -> C:\WINDOWS\system32\faultrep.dll 0013FDB8 7C97E140 ntdll.dll!NlsMbOemCodePageTag+0x98 0013FDBC 0013F3BC 0013FDC0 7C90E920 ntdll.dll!strchr+0x113 0013FDC4 7C910060 ntdll.dll!RtlFreeHeap+0x133 0013FDC8 FFFFFFFF 0013FDCC 7C91005D ntdll.dll!RtlFreeHeap+0x130 0013FDD0 7C911452 ntdll.dll!RtlDeleteCriticalSection+0xd8 0013FDD4 7C911483 ntdll.dll!RtlDeleteCriticalSection+0x109 0013FDD8 7C97E120 ntdll.dll!NlsMbOemCodePageTag+0x78 0013FDDC 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013FDE0 00163FC8 -> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0013FDE4 00000038 0013FDE8 00153A3C 0013FDEC 7FFDF000 -> 84 DD 13 00 00 00 14 00 00 B0 13 00 00 00 00 00 0013FDF0 0013F3A4 0013FDF4 00000000 0013FDF8 0013F400 0013FDFC 7C90E920 ntdll.dll!strchr+0x113 0013FE00 7C911468 ntdll.dll!RtlDeleteCriticalSection+0xee 0013FE04 FFFFFFFF 0013FE08 7C911460 ntdll.dll!RtlDeleteCriticalSection+0xe6 0013FE0C 00150000 -> Actx 0013FE10 7C9113F2 ntdll.dll!RtlDeleteCriticalSection+0x78 0013FE14 00153A3C 0013FE18 00153A28 0013FE1C 00000000 0013FE20 00163C00 -> NDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0 0013FE24 0001E168 0013FE28 00169A24 -> 50 03 16 00 5C 00 54 00 65 00 6D 00 05 00 03 00 0013FE2C 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FE30 00425EBF ManageACL_32.exe+0x25ebf 0013FE34 0013FF3C -> `FF 0013FE38 004784D0 ManageACL_32.exe+0x784d0 0013FE3C 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FE40 0013FE6C 0013FE44 0045C984 ManageACL_32.exe+0x5c984 0013FE48 0013FF3C -> `FF 0013FE4C D3EA5882 0013FE50 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FE54 001699C0 -> 63 73 6D E0 01 00 00 00 00 00 00 00 00 00 00 00 0013FE58 0013FEC0 0013FE5C 0013FE4C 0013FE60 0013FF08 0013FE64 00460CF8 ManageACL_32.exe+0x60cf8 0013FE68 00000000 0013FE6C 0013FEA0 0013FE70 0045C703 ManageACL_32.exe+0x5c703 0013FE74 00169A20 -> AC 39 46 00 50 03 16 00 5C 00 54 00 65 00 6D 00 0013FE78 0013FF3C -> `FF 0013FE7C 0000000C 0013FE80 004784D0 ManageACL_32.exe+0x784d0 0013FE84 00000026 0013FE88 00000000 0013FE8C 00000001 0013FE90 0045CF18 ManageACL_32.exe+0x5cf18 0013FE94 00000054 0013FE98 00434752 ManageACL_32.exe+0x34752 0013FE9C 004784D0 ManageACL_32.exe+0x784d0 0013FEA0 0013FF14 0013FEA4 0045CA82 ManageACL_32.exe+0x5ca82 0013FEA8 0013FEC0 0013FEAC 00000000 0013FEB0 D3EA59FA 0013FEB4 00000026 0013FEB8 004615D0 ManageACL_32.exe+0x615d0 0013FEBC 00000028 0013FEC0 E06D7363 0013FEC4 00000001 0013FEC8 00000000 0013FECC 00000000 0013FED0 00000003 0013FED4 19930520 0013FED8 0013FF3C -> `FF 0013FEDC 004784B4 ManageACL_32.exe+0x784b4 0013FEE0 0013FECC 0013FEE4 7C9115C6 ntdll.dll!RtlInitializeCriticalSectionAndSpinCount+0xac 0013FEE8 0013FFB0 0013FEEC 00000000 0013FEF0 00000000 0013FEF4 001699C0 -> 63 73 6D E0 01 00 00 00 00 00 00 00 00 00 00 00 0013FEF8 001699C0 -> 63 73 6D E0 01 00 00 00 00 00 00 00 00 00 00 00 0013FEFC 00000000 0013FF00 0013FF0C 0013FF04 0013FEB0 0013FF08 0013FF4C 0013FF0C 00460D36 ManageACL_32.exe+0x60d36 0013FF10 00000003 0013FF14 0013FF58 0013FF18 0045CD00 ManageACL_32.exe+0x5cd00 0013FF1C 004835A4 ManageACL_32.exe+0x835a4 0013FF20 0013FF3C -> `FF 0013FF24 004784B4 ManageACL_32.exe+0x784b4 0013FF28 00000000 0013FF2C D3EA59B6 0013FF30 00000026 0013FF34 004615D0 ManageACL_32.exe+0x615d0 0013FF38 00000028 0013FF3C 00464660 ManageACL_32.exe+0x64660 0013FF40 00464668 -> bad allocation 0013FF44 00000000 0013FF48 00000000 0013FF4C 0013FFB0 0013FF50 00460D81 ManageACL_32.exe+0x60d81 0013FF54 00000000 0013FF58 0013FF7C 0013FF5C 00401551 ManageACL_32.exe+0x1551 0013FF60 004835A4 ManageACL_32.exe+0x835a4 0013FF64 00434CF9 ManageACL_32.exe+0x34cf9 0013FF68 982E6B30 0013FF6C 01D21713 0013FF70 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013FF74 00401547 ManageACL_32.exe+0x1547 0013FF78 D3EA5992 0013FF7C 0013FFC0 0013FF80 0042391C ManageACL_32.exe+0x2391c 0013FF84 00461538 ManageACL_32.exe+0x61538 0013FF88 004615D8 ManageACL_32.exe+0x615d8 0013FF8C D3EA592E 0013FF90 982E6B30 0013FF94 01D21713 0013FF98 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013FF9C 0013FF00 0013FFA0 C000001D 0013FFA4 00D21713 0013FFA8 0013FF8C 0013FFAC 0013FA40 0013FFB0 0013FFE0 0013FFB4 00429BF0 ManageACL_32.exe+0x29bf0 0013FFB8 D3BE243E 0013FFBC 00000000 0013FFC0 0013FFF0 0013FFC4 7C81776F kernel32.dll!RegisterWaitForInputIdle+0x49 0013FFC8 982E6B30 0013FFCC 01D21713 0013FFD0 7FFDA000 -> 00 00 00 00 FF FF FF FF 00 00 40 00 90 1E 26 00 0013FFD4 C000001D 0013FFD8 0013FFC8 0013FFDC 0013FA54 0013FFE0 FFFFFFFF 0013FFE4 7C839AB0 kernel32.dll!ValidateLocale+0x2b0 0013FFE8 7C817778 kernel32.dll!RegisterWaitForInputIdle+0x52 0013FFEC 00000000 0013FFF0 00000000 0013FFF4 00000000 0013FFF8 00423A1D ManageACL_32.exe+0x23a1d 0013FFFC 00000000