Gen:Variant.Kazy.563771 (BitDefender), UDS:DangerousObject.Multi.Generic (Kaspersky), Trojan.Win32.Generic.pak!cobra (VIPRE), Win32.VirLock.10 (DrWeb), Gen:Variant.Kazy.563771 (B) (Emsisoft), W32/VirRansom.b (McAfee), WS.Reputation.1 (Symantec), Packed.Win32.Gena (Ikarus), Gen:Variant.Kazy.563771 (FSecure), LockScreen.BO (AVG), Win32:Evo-gen [Susp] (Avast), TROJ_GEN.R08NC0RBP15 (TrendMicro), Gen:Variant.Kazy.563771 (AdAware), ZeroAccess.YR (Lavasoft MAS)Behaviour: Ransom, Trojan, Packed
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: cfdabe64f3e5325c1bb1661cac02628d
SHA1: db179f189f0ecc8c3b71e070c2c5cf31d95873de
SHA256: 6451fa4caff54709cb4a5608fe412fa19415d8dd400b4e6550b907552ffe1619
SSDeep: 49152:NDuYnC/E8dyYoWA8zJ7mLbXWsYxo1dT2LmxtnH:0Yw5Tm7WsY n
Size: 1954304 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: PC Utilities Software Limited
Created at: 2015-02-07 11:53:36
Analyzed on: WindowsXP SP3 32-bit
Summary: Ransom. Disables the compromised computer or restricts access to certain data so that the victim can no longer use it. The victim is expected to send payment to the hijacker to restore access to the blocked data or re-enable the system.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
AdobeARM.exe:1512
%original file name%.exe:584
The Trojan injects its code into the following process(es):
NesIMIQs.exe:500
fGAwoYMM.exe:1072
reIEcoQI.exe:1552
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process fGAwoYMM.exe:1072 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe (11518 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe (7385 bytes)
C:\totalcmd\TOTALCMD.EXE.exe (35505 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe (7385 bytes)
C:\totalcmd\TCMADMIN.EXE.exe (7433 bytes)
C:\totalcmd\TCUNINST.EXE.exe (7385 bytes)
C:\totalcmd\TcUsbRun.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\KAAo.txt (55978 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe (7433 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe (7433 bytes)
C:\totalcmd\TCMDX32.EXE.exe (7433 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe (7971 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe (10177 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe (7385 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp (0 bytes)
C:\totalcmd\TCUNINST.EXE (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp (0 bytes)
C:\totalcmd\TCMDX32.EXE (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp (0 bytes)
C:\totalcmd\TCMADMIN.EXE (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg (0 bytes)
C:\totalcmd\TOTALCMD.EXE (0 bytes)
The process AdobeARM.exe:1512 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\ArmUI.ini (190 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AdobeARM.log (1308 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\ArmUI.ini (0 bytes)
The process %original file name%.exe:584 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe (7761 bytes)
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe (7737 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AdobeARM.exe (6400 bytes)
%Documents and Settings%\All Users\JuwEIgUE\reIEcoQI.exe (7785 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IsQkUUMg.bat (4 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IsQkUUMg.bat (0 bytes)
Registry activity
The process NesIMIQs.exe:500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3D A0 4F 64 4D B6 61 0D 50 5B E2 0B AA 4A 28 4C"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NesIMIQs.exe" = "%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe"
The process fGAwoYMM.exe:1072 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4E FA 5C C4 5F 91 1B 6A B2 B0 9B ED 97 E4 E6 9F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"fGAwoYMM.exe" = "%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe"
The process reIEcoQI.exe:1552 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2B 42 0B 5C EE BA B2 B3 FE 03 07 6C D4 80 3D 9F"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NesIMIQs.exe" = "%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe"
The process AdobeARM.exe:1512 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "12 FE B9 C9 EE 86 ED 56 4C DC 2C 7A 90 2A F8 38"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Adobe\Adobe ARM\1.0\ARM]
"iLastSvcSuccess"
[HKCU\Software\Adobe\Adobe ARM\1.0\ARM]
"iNotify"
The process %original file name%.exe:584 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "21 FE E6 31 AE A6 A9 9A 86 0F 86 C9 F0 66 90 B0"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"fGAwoYMM.exe" = "%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe"
The Trojan adds the reference to itself to be executed when a user logs on:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "%System%\userinit.exe,%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe,"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NesIMIQs.exe" = "%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe"
Dropped PE files
MD5 | File path |
---|---|
cc788b8ded62da2d701d2ff1940b9da0 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe |
eb8b4ad56cf35c9884eccb60d0e90f86 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe |
9981c7af30d9fef16c5bffd1cef79c23 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe |
61d78994fee39d6e48e2ca4c483e5b2c | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe |
8b95258ea705c0300be266d66dbd77b2 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe |
1be5575844285067c9ea2bd13bd8897c | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe |
29da8c918c26be20d8a74c7f3691ce12 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe |
50fec8745410dc0a1faf05c3f2c89997 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe |
256dafb5dbfbf8e43b3776f6333ab059 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe |
f6e854557dda24853c1649fcb154c61c | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe |
7e1a5ca6b22a30bd7a59f4ba7ec7c222 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe |
ac8f56e38f740e37503c3ab189c85c29 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe |
d91fff5ce59ff3953b554f7d3de76810 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe |
4a4eb8575b775588ea70ac3c067fa0d8 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe |
3feb3da07d736dbdb77f6bf77c489db7 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe |
d666514ce43cfbce97e9cbebd3b2a617 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe |
685ded4b4d793ae5c8a8f71e0bcc9dff | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe |
f5f6ad87cdb72f08a35ea0f36d583cb8 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe |
f573a51d26555839e9961f43dd1682a1 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe |
b18338a132637adb4bbc0bb44007b639 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe |
4a3b6c841b8b8bc9c28ca796d6a784ac | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe |
556665a993d6e37659048ba2c71a7f7e | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe |
36a0e9756955d08b77af597fa57f9146 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe |
860ab5b5c215306cdd6b9858a97e023e | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp.exe |
74fa9202fbd56e6e0676e1ddf6750b1e | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe |
0bd0571af8e28e3dc8cd0487cfb157f4 | c:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe |
5a5bb2ecbde31ef8925fbefa6f129bcd | c:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe |
49af236fd0ee290daef1891289d75672 | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe |
e07f9272d81b759efae90ce94c9fba0d | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe |
36eb83f53768722f6bf1ceca30af9720 | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe |
0d59e9b91237fdb3ed8aceebddb53c1d | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe |
e89a3213b1f83ee87df507dda57f96ba | c:\Documents and Settings\All Users\JuwEIgUE\reIEcoQI.exe |
516ddd1bfa7dda43b735d875b0f0667f | c:\Documents and Settings\All Users\hcYYccwo\NesIMIQs.exe |
47ea5f76fab723c61ab4a0d79bad512c | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\AdobeARM.exe |
624751d10357a625e6a2655e4808dbfe | c:\Documents and Settings\"%CurrentUserName%"\dUskcAww\fGAwoYMM.exe |
1008bbef525ccede4ed77aeb7b8c6b2c | c:\Perl\eg\IEExamples\ie_animated.gif.exe |
0e4946fd67018ce9f85668f41c3e3523 | c:\Perl\eg\IEExamples\psbwlogo.gif.exe |
a15fad7f8c93534c44a65d13f1b719a9 | c:\Perl\eg\aspSamples\ASbanner.gif.exe |
080e7b4be5559e2a2162ff805a344b51 | c:\Perl\eg\aspSamples\Main_Banner.gif.exe |
47716d90d3714945cb1099820cc8b365 | c:\Perl\eg\aspSamples\psbwlogo.gif.exe |
ab7fb6574a57da3a1adea64f9621e157 | c:\Perl\html\images\AS_logo.gif.exe |
328f1cbf78a7aff6f14386630d237485 | c:\Perl\html\images\PerlCritic_run.png.exe |
df5b5ead59257c1f45448b4d86868c90 | c:\Perl\html\images\aslogo.gif.exe |
fb45e00074e2e95bc288e21954c05414 | c:\Perl\html\images\ppm_gui.png.exe |
71944c5e7cf9dbb645643c4b95b30661 | c:\Perl\lib\ActivePerl\PPM\images\gecko.png.exe |
e085e9663e5acae08a6e572a5c76ee24 | c:\Perl\lib\ActivePerl\PPM\images\perl_48x48.png.exe |
e17bf3d178084b1b24e3166f69b937df | c:\Perl\lib\Devel\NYTProf\js\asc.png.exe |
6f653fde11c622574b659214dea68afd | c:\Perl\lib\Devel\NYTProf\js\bg.png.exe |
d7720ac286d49f3d5996bf25b7a2bbbe | c:\Perl\lib\Devel\NYTProf\js\desc.png.exe |
4b6f8b2aea57913e21755948b9e0c4b5 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient.png.exe |
b361363a3ddcf18c80a83de8501d6a91 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient20.png.exe |
200aa5edfc06a3a834313c8cf7654a74 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient30.png.exe |
9bf72c07a1e64f4932cdc0a44e40636b | c:\Perl\lib\Devel\NYTProf\js\jit\gradient40.png.exe |
c3509dce1018c4231fbfd98c9f7acdfe | c:\Perl\lib\Devel\NYTProf\js\jit\gradient50.png.exe |
26c77a3d8950a1d0e488a8025a8b06c9 | c:\Perl\lib\Mozilla\CA\cacert.pem.exe |
511c2d55fd3d3a36efb163c8790c0e67 | c:\totalcmd\TCMADMIN.EXE.exe |
f4f24e0c2ca8766bdcf7c141f888ab44 | c:\totalcmd\TCMDX32.EXE.exe |
cb1621b348a74b8647e4859f63d65916 | c:\totalcmd\TCUNINST.EXE.exe |
4fa04d60fbc6549b3d6467c0f1bdd604 | c:\totalcmd\TOTALCMD.EXE.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
AdobeARM.exe:1512
%original file name%.exe:584 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe (11518 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe (7385 bytes)
C:\totalcmd\TOTALCMD.EXE.exe (35505 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe (7385 bytes)
C:\totalcmd\TCMADMIN.EXE.exe (7433 bytes)
C:\totalcmd\TCUNINST.EXE.exe (7385 bytes)
C:\totalcmd\TcUsbRun.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\KAAo.txt (55978 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe (7433 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe (7433 bytes)
C:\totalcmd\TCMDX32.EXE.exe (7433 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe (7971 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe (10177 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe (7385 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ArmUI.ini (190 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AdobeARM.log (1308 bytes)
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe (7761 bytes)
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe (7737 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AdobeARM.exe (6400 bytes)
%Documents and Settings%\All Users\JuwEIgUE\reIEcoQI.exe (7785 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IsQkUUMg.bat (4 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NesIMIQs.exe" = "%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"fGAwoYMM.exe" = "%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe" - Remove the references to the Trojan by modifying the following registry value(s) (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "%System%\userinit.exe,%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe," - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 1949696 | 1947136 | 5.31499 | 57273593a36eb11cc9636fe174ba9096 |
.rdata | 1953792 | 4096 | 512 | 2.15094 | 2972156c185ddda1362b672f173d4d97 |
.data | 1957888 | 5 | 512 | 0.067931 | 6d948125d16c8e2013f3b1107f8a5d22 |
.rsrc | 1961984 | 4444 | 4608 | 3.47705 | 2caefe6204a241140411be0308412d28 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://google.com/ | 216.58.209.206 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET / HTTP/1.1
Host: google.com
HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Location: hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=kwwSVZ-zLoyu8weJ44KACA
Content-Length: 262
Date: Wed, 25 Mar 2015 01:17:07 GMT
Server: GFE/2.0
Alternate-Protocol: 80:quic,p=0.5
<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>.<H1>302 Moved</H1>.The document has moved.<A HREF="hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=kwwSVZ-zLoyu8weJ44KACA">here</A>...</BODY></HTML>..HTTP/1.1 302 Found..Cache-Control: private..Content-Type: text/html; charset=UTF-8..Location: hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=kwwSVZ-zLoyu8weJ44KACA..Content-Length: 262..Date: Wed, 25 Mar 2015 01:17:07 GMT..Server: GFE/2.0..Alternate-Protocol: 80:quic,p=0.5..<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>.<H1>302 Moved</H1>.The document has moved.<A HREF="hXXp://www.google.com.ua/?gfe_rd=cr&ei=kwwSVZ-zLoyu8weJ44KACA">here</A>...</BODY></HTML>....
GET / HTTP/1.1
Host: google.com
HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Location: hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=lQwSVbX-JIqu8wes14G4Bw
Content-Length: 262
Date: Wed, 25 Mar 2015 01:17:09 GMT
Server: GFE/2.0
Alternate-Protocol: 80:quic,p=0.5
<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>.<H1>302 Moved</H1>.The document has moved.<A HREF="hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=lQwSVbX-JIqu8wes14G4Bw">here</A>...</BODY></HTML>..HTTP/1.1 302 Found..Cache-Control: private..Content-Type: text/html; charset=UTF-8..Location: hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=lQwSVbX-JIqu8wes14G4Bw..Content-Length: 262..Date: Wed, 25 Mar 2015 01:17:09 GMT..Server: GFE/2.0..Alternate-Protocol: 80:quic,p=0.5..<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>.<H1>302 Moved</H1>.The document has moved.<A HREF="hXXp://www.google.com.ua/?gfe_rd=cr&ei=lQwSVbX-JIqu8wes14G4Bw">here</A>...</BODY></HTML>....
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
fGAwoYMM.exe_1072:
.text
.text
.rdata
.rdata
@.data
@.data
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
Microsoft Windows
Microsoft Windows
{Nb%6x
{Nb%6x
P:.wX
P:.wX
P:.tYZ
P:.tYZ
P:\ sm#
P:\ sm#
P:\C_k#
P:\C_k#
).Lla!T$
).Lla!T$
9.Lny!G$
9.Lny!G$
nz.nno?no=no:nl
nz.nno?no=no:nl
ntdll.dll
ntdll.dll
kernel32.dll
kernel32.dll
user32.dll
user32.dll
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
fGAwoYMM.exe_1072_rwx_00401000_000EA000:
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
Microsoft Windows
Microsoft Windows
{Nb%6x
{Nb%6x
P:.wX
P:.wX
P:.tYZ
P:.tYZ
P:\ sm#
P:\ sm#
P:\C_k#
P:\C_k#
).Lla!T$
).Lla!T$
9.Lny!G$
9.Lny!G$
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
fGAwoYMM.exe_1072_rwx_009A0000_00001000:
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp
NesIMIQs.exe_500:
.text
.text
.rdata
.rdata
@.data
@.data
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
Microsoft Windows
Microsoft Windows
?!%C"
?!%C"
%uNaO
%uNaO
.YtUO
.YtUO
LoadKeyboardLayoutW
LoadKeyboardLayoutW
user32.dll
user32.dll
ntdll.dll
ntdll.dll
ole32.dll
ole32.dll
advapi32.dll
advapi32.dll
kernel32.dll
kernel32.dll
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
fGAwoYMM.exe_1072_rwx_00A00000_00001000:
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM
fGAwoYMM.exe_1072_rwx_00A10000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs
fGAwoYMM.exe_1072_rwx_00A30000_000E9000:
C{?%f{[
C{?%f{[
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
4%UMv
4%UMv
4%UEInb
4%UEInb
%uNaO
%uNaO
.YtUO
.YtUO
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
fGAwoYMM.exe_1072_rwx_00E20000_00001000:
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.inf
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.inf
fGAwoYMM.exe_1072_rwx_00E30000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.inf
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.inf
reIEcoQI.exe_1552:
.text
.text
.rdata
.rdata
@.data
@.data
C{?%f{[
C{?%f{[
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
4%UMv
4%UMv
4%UEInb
4%UEInb
2software\microsoft\windows\currentversion\run
2software\microsoft\windows\currentversion\run
%uNaO
%uNaO
.YtUO
.YtUO
ZwReplyWaitReceivePortEx
ZwReplyWaitReceivePortEx
ntdll.dll
ntdll.dll
user32.dll
user32.dll
kernel32.dll
kernel32.dll
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
fGAwoYMM.exe_1072_rwx_00E40000_00001000:
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe
fGAwoYMM.exe_1072_rwx_00E50000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe
fGAwoYMM.exe_1072_rwx_00E80000_00001000:
fGAwoYMM.exe
fGAwoYMM.exe
fGAwoYMM.exe_1072_rwx_00E90000_00001000:
NesIMIQs.exe
NesIMIQs.exe
fGAwoYMM.exe_1072_rwx_00EA0000_00001000:
taskkill /FI "USERNAME eq adm" /F /IM fGAwoYMM.exe
taskkill /FI "USERNAME eq adm" /F /IM fGAwoYMM.exe
fGAwoYMM.exe_1072_rwx_00EB0000_00001000:
taskkill /FI "USERNAME eq adm" /F /IM NesIMIQs.exe
taskkill /FI "USERNAME eq adm" /F /IM NesIMIQs.exe
fGAwoYMM.exe_1072_rwx_00EC0000_00001000:
%Documents and Settings%\All Users\JuwEIgUE\reIEcoQI.exe
%Documents and Settings%\All Users\JuwEIgUE\reIEcoQI.exe
fGAwoYMM.exe_1072_rwx_00ED0000_00001000:
%Documents and Settings%\All Users\KAAo.txt
%Documents and Settings%\All Users\KAAo.txt
fGAwoYMM.exe_1072_rwx_00EE0000_00001000:
notepad.exe "%Documents and Settings%\All Users\KAAo.txt"
notepad.exe "%Documents and Settings%\All Users\KAAo.txt"
fGAwoYMM.exe_1072_rwx_00EF0000_00001000:
%Documents and Settings%\All Users\JuwEIgUE
%Documents and Settings%\All Users\JuwEIgUE
fGAwoYMM.exe_1072_rwx_01170000_00001000:
.text
.text
`.rdata
`.rdata
@.data
@.data
fGAwoYMM.exe_1072_rwx_01190000_02300000:
advapi32.dll
advapi32.dll
user32.dll
user32.dll
kernel32.dll
kernel32.dll
A-.fvC*T
A-.fvC*T
{( .Kx\|
{( .Kx\|
.yPcQ
.yPcQ
SbN&|%U
SbN&|%U
xy%dW
xy%dW
xI%d=
xI%d=
p.qUu
p.qUu
Qkeym
Qkeym
K=.ea
K=.ea
-h.axw(
-h.axw(
.KP^*,
.KP^*,
N%xQx
N%xQx
.gtnf
.gtnf
-AX}{
-AX}{
x]t
x]t
s%U'#VUi
s%U'#VUi
.HqeR
.HqeR
g%S&O
g%S&O
w<.mvpj>
w<.mvpj>
[YD.zEF
[YD.zEF
r.tdX
r.tdX
-hv}Sv
-hv}Sv
^@.VT~
^@.VT~
_s2,ÃŽp
_s2,ÃŽp
K;s.de
K;s.de
CB.PT
CB.PT
; CoQ.JIm
; CoQ.JIm
!q.vH
!q.vH
U9.LB@
U9.LB@
c~Fd.ew
c~Fd.ew
g9H!ßM
g9H!ßM
=p%C`T)
=p%C`T)
.Gz}d
.Gz}d
o.VpI_
o.VpI_
aC.iV
aC.iV
,r{4%C
,r{4%C
.GFjh
.GFjh
.IKIf
.IKIf
1`I.Tu
1`I.Tu
">.KD
">.KD
HPË
HPË
[T.Sx
[T.Sx
']o.Ze
']o.Ze
d%uc!
d%uc!
O.zh?
O.zh?
.il<:di>
.il<:di>
&j.Up
&j.Up
k%Si'
k%Si'
*3.Yx
*3.Yx
5%uFl}
5%uFl}
n%X8^
n%X8^
!.HVq
!.HVq
.Ol'z
.Ol'z
CG.ua
CG.ua
8YE.CX
8YE.CX
v.MW4
v.MW4
FJ.OW@3
FJ.OW@3
k.Zk*
k.Zk*
nc.yg
nc.yg
%UrWl
%UrWl
.bNJ'_[
.bNJ'_[
y%XdQ
y%XdQ
so.dy
so.dy
>)'!49'}
>)'!49'}
E.mi5-
E.mi5-
w9.Ux'
w9.Ux'
(.KbAJ
(.KbAJ
`&(.KvAJ
`&(.KvAJ
&.KvAJJ
&.KvAJJ
67.TF
67.TF
w.WK[
w.WK[
>4.WKZ
>4.WKZ
.Zp g'
.Zp g'
zFTp
zFTp
N:\BP
N:\BP
%xK2Ty
%xK2Ty
b%xlUc_
b%xlUc_
jsQl
jsQl
.KW:BoG8
.KW:BoG8
;L.Af
;L.Af
?<.tq>
?<.tq>
3a.GM
3a.GM
pK8%u
pK8%u
pK8%uK8
pK8%uK8
kUU.iUT.n
kUU.iUT.n
i.UUh
i.UUh
f.XUe
f.XUe
.*UM.qUK.wUI.uUG.{UE.yUC.
.*UM.qUK.wUI.uUG.{UE.yUC.
UA.}U_.cU].aU[.gUY.eUW.kU
UA.}U_.cU].aU[.gUY.eUW.kU
$wUI.uUb.\
$wUI.uUb.\
'UG.{UE.yUC.
'UG.{UE.yUC.
.UUg.
.UUg.
U5.aU[.gUY.eUW.kUU.iUt.NUr.LUp.
U5.aU[.gUY.eUW.kUU.iUt.NUr.LUp.
O.sUM.qUK.wUI.uUG.{UE.yUC.
O.sUM.qUK.wUI.uUG.{UE.yUC.
w.LnwP
w.LnwP
.Gal['
.Gal['
.dS/"i3v@
.dS/"i3v@
fGAwoYMM.exe_1072_rwx_03B90000_01E00000:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
u%Uh`
u%Uh`
QSSSh
QSSSh
QVSSh
QVSSh
t.PSh
t.PSh
T$lRSSh| "
T$lRSSh| "
UDPQRh
UDPQRh
L$ QSSh
L$ QSSh
L$,QSSh
L$,QSSh
QSSShlVU
QSSShlVU
RVSShlVU
RVSShlVU
t.Ph\
t.Ph\
tGHt.Ht&
tGHt.Ht&
operand of unlimited repeat could match the empty string
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
POSIX named classes are supported only within a class
erroffset passed as NULL
erroffset passed as NULL
POSIX collating elements are not supported
POSIX collating elements are not supported
this version of PCRE is not compiled with PCRE_UTF8 support
this version of PCRE is not compiled with PCRE_UTF8 support
PCRE does not support \L, \l, \N{name}, \U, or \u
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with PCRE_UCP support
this version of PCRE is not compiled with PCRE_UCP support
\N is not supported in a class
\N is not supported in a class
inflate 1.2.5 Copyright 1995-2010 Mark Adler
inflate 1.2.5 Copyright 1995-2010 Mark Adler
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
operator
operator
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
RtlRunOnceExecuteOnce
RtlRunOnceExecuteOnce
advapi32_hack::try_hack: bad PE passed
advapi32_hack::try_hack: bad PE passed
advapi32_hack::try_hack: cannot read import table
advapi32_hack::try_hack: cannot read import table
advapi32_hack::try_hack: cannot find section .text
advapi32_hack::try_hack: cannot find section .text
.data
.data
advapi32_hack::try_hack: cannot find section .data
advapi32_hack::try_hack: cannot find section .data
advapi32_hack::try_hack: cannot read section .text
advapi32_hack::try_hack: cannot read section .text
Cannot read module %s, error %d
Cannot read module %s, error %d
Cannot read exports of %s, error %d
Cannot read exports of %s, error %d
advapi32_hack::try_hack: cannot read exports, error %d
advapi32_hack::try_hack: cannot read exports, error %d
.apiset
.apiset
Bad .apiset catalog - don`t fit in section
Bad .apiset catalog - don`t fit in section
String in cat item %d not in section
String in cat item %d not in section
Value in cat item %d not in section
Value in cat item %d not in section
Bad referred in cat item %d
Bad referred in cat item %d
Double mapped value in cat item %d not in section
Double mapped value in cat item %d not in section
Bad double referred in cat item %d
Bad double referred in cat item %d
BaseSrvRegisterWowExec
BaseSrvRegisterWowExec
BaseSrvGetProcessShutdownParam
BaseSrvGetProcessShutdownParam
BaseSrvSetProcessShutdownParam
BaseSrvSetProcessShutdownParam
basesrv.dll
basesrv.dll
Unknown size of BaseServerApiDispatchTable: %d
Unknown size of BaseServerApiDispatchTable: %d
ServerDll[%d] %p
ServerDll[%d] %p
csrsrv.dll
csrsrv.dll
CsrExecServerThread
CsrExecServerThread
ServerDll[%d]:
ServerDll[%d]:
ApiDispatchTable: %p %s
ApiDispatchTable: %p %s
ConnectRoutine: %p %s
ConnectRoutine: %p %s
DisconnectRoutine: %p %s
DisconnectRoutine: %p %s
HardErrorRoutine: %p %s
HardErrorRoutine: %p %s
AddProcessRoutine: %p %s
AddProcessRoutine: %p %s
ShutdownProcessRoutine: %p %s
ShutdownProcessRoutine: %p %s
Cannot open dir %S, error %d
Cannot open dir %S, error %d
clean_old_drvs: error %d on deleting file %S
clean_old_drvs: error %d on deleting file %S
Cannot find resource %X
Cannot find resource %X
Cannot load resource %X
Cannot load resource %X
Resource %d has zero length
Resource %d has zero length
Cannot lock resource %X
Cannot lock resource %X
Cannot unpack resource %X
Cannot unpack resource %X
Cannot create file %S, error %d
Cannot create file %S, error %d
1.2.5
1.2.5
Decompress buffer %d bytes too small
Decompress buffer %d bytes too small
DxDvpWaitForVideoPortSync
DxDvpWaitForVideoPortSync
DxDvpUpdateVideoPort
DxDvpUpdateVideoPort
DxDvpGetVideoPortConnectInfo
DxDvpGetVideoPortConnectInfo
DxDvpGetVideoPortOutputFormats
DxDvpGetVideoPortOutputFormats
DxDvpGetVideoPortLine
DxDvpGetVideoPortLine
DxDvpGetVideoPortInputFormats
DxDvpGetVideoPortInputFormats
DxDvpGetVideoPortFlipStatus
DxDvpGetVideoPortFlipStatus
DxDvpGetVideoPortField
DxDvpGetVideoPortField
DxDvpGetVideoPortBandwidth
DxDvpGetVideoPortBandwidth
DxDvpFlipVideoPort
DxDvpFlipVideoPort
DxDvpDestroyVideoPort
DxDvpDestroyVideoPort
DxDvpCreateVideoPort
DxDvpCreateVideoPort
DxDvpCanCreateVideoPort
DxDvpCanCreateVideoPort
DxDdSetColorKey
DxDdSetColorKey
Cannot read gaDxgFuncs handlers, readed %X bytes
Cannot read gaDxgFuncs handlers, readed %X bytes
.rdata
.rdata
Cannot read DxgCoreInterface handlers, readed %X bytes
Cannot read DxgCoreInterface handlers, readed %X bytes
Unknown acpi table version: %X
Unknown acpi table version: %X
SBP2PORT_Mask
SBP2PORT_Mask
STORMINIPORT_Mask
STORMINIPORT_Mask
STORPORT_Mask
STORPORT_Mask
TCPIP6_Mask
TCPIP6_Mask
WSOCKTRANSPORT_Mask
WSOCKTRANSPORT_Mask
FCPORT_Mask
FCPORT_Mask
SOFTPCI_Mask
SOFTPCI_Mask
TCPIP_Mask
TCPIP_Mask
SCSIMINIPORT_Mask
SCSIMINIPORT_Mask
SCSIPORT_Mask
SCSIPORT_Mask
Unknown KdComponentTableSize size %X
Unknown KdComponentTableSize size %X
dump_kd_masks return %X bytes, error %d, ntstatus %X
dump_kd_masks return %X bytes, error %d, ntstatus %X
dump_kd_masks return %X bytes, error %d
dump_kd_masks return %X bytes, error %d
dump_kd_masks(%s) return %X bytes, error %d, ntstatus %X
dump_kd_masks(%s) return %X bytes, error %d, ntstatus %X
dump_kd_masks(%s) return %X bytes, error %d
dump_kd_masks(%s) return %X bytes, error %d
%-*s: %X
%-*s: %X
read_kopts_length(%s) return %X bytes, error %d, ntstatus %X
read_kopts_length(%s) return %X bytes, error %d, ntstatus %X
read_kopts_length(%s) return %X bytes, error %d
read_kopts_length(%s) return %X bytes, error %d
Cannot alloc %X bytes
Cannot alloc %X bytes
Cannot realloc %X bytes for %s
Cannot realloc %X bytes for %s
read_kopts(%s) return %X bytes, error %d, ntstatus %X
read_kopts(%s) return %X bytes, error %d, ntstatus %X
read_kopts(%s) return %X bytes, error %d
read_kopts(%s) return %X bytes, error %d
%S (%s): %X
%S (%s): %X
%S (%s):
%S (%s):
dump_kopts(%s) return %X bytes, error %d, ntstatus %X
dump_kopts(%s) return %X bytes, error %d, ntstatus %X
dump_kopts(%s) return %X bytes, error %d
dump_kopts(%s) return %X bytes, error %d
MmSupportWriteWatch
MmSupportWriteWatch
KiPassiveWatchdogTimeout
KiPassiveWatchdogTimeout
ViImageExecutionOptions
ViImageExecutionOptions
DbgkErrorPortStartTimeout
DbgkErrorPortStartTimeout
DbgkErrorPortCommTimeout
DbgkErrorPortCommTimeout
MmDisablePagingExecutive
MmDisablePagingExecutive
CmDefaultLanguageId
CmDefaultLanguageId
DbgkpMaxModuleMsgs
DbgkpMaxModuleMsgs
IoCountOperations
IoCountOperations
KeDelayExecutionThread
KeDelayExecutionThread
resolve_IoFreeIrp: bad addr of %s
resolve_IoFreeIrp: bad addr of %s
get_interrupt_dispatch: cannot alloc %d bytes
get_interrupt_dispatch: cannot alloc %d bytes
Unknown kernel options: %S
Unknown kernel options: %S
PsGetProcessWin32WindowStation
PsGetProcessWin32WindowStation
KeIsExecutingDpc
KeIsExecutingDpc
bad addr of KeIsExecutingDpc
bad addr of KeIsExecutingDpc
Bad pnp handler item %d (%d)
Bad pnp handler item %d (%d)
Cannot find %s
Cannot find %s
ks.sys: cannot get KoCreateInstance
ks.sys: cannot get KoCreateInstance
ImportContext
ImportContext
ExportContext
ExportContext
SpChangeAccountPasswordFn
SpChangeAccountPasswordFn
CallPackagePassthrough
CallPackagePassthrough
%SystemRoot%\System32\
%SystemRoot%\System32\
GetServiceAccountPassword
GetServiceAccountPassword
DPAPIPasswordChangeForGMSA
DPAPIPasswordChangeForGMSA
GetCredentialKey
GetCredentialKey
INotifyPasswordChanged
INotifyPasswordChanged
%s PolicyChangeNotificationCallbacks
%s PolicyChangeNotificationCallbacks
PolicyChangeNotificationCallback[%d]: %d items
PolicyChangeNotificationCallback[%d]: %d items
[%d] %p %p %p %p %s
[%d] %p %p %p %p %s
lsasrv_hack::try_hack: bad PE passed
lsasrv_hack::try_hack: bad PE passed
lsasrv_hack::try_hack: cannot find section .data
lsasrv_hack::try_hack: cannot find section .data
lsasrv_hack::try_hack: cannot read section .data
lsasrv_hack::try_hack: cannot read section .data
lsasrv_hack::try_hack: bad section passed
lsasrv_hack::try_hack: bad section passed
lsasrv_hack::try_hack: cannot read exports, error %d
lsasrv_hack::try_hack: cannot read exports, error %d
LsaICallPackagePassthrough
LsaICallPackagePassthrough
lsasrv.dll
lsasrv.dll
VaultLogonSessionNotification: %p %s
VaultLogonSessionNotification: %p %s
Start of driver %S failed !
Start of driver %S failed !
WSPJoinLeaf
WSPJoinLeaf
MSAFD_WSPSendMsg
MSAFD_WSPSendMsg
MSAFD_WSPRecvMsg
MSAFD_WSPRecvMsg
mswsock.dll
mswsock.dll
CheckProc: cannot open process PID %d, error %d, ntstatus %X
CheckProc: cannot open process PID %d, error %d, ntstatus %X
CheckProc: cannot open process PID %d, error %d
CheckProc: cannot open process PID %d, error %d
threaded_processes_checker exception occured, error %X
threaded_processes_checker exception occured, error %X
MyWindowsChecker: len %d, kernel name %s
MyWindowsChecker: len %d, kernel name %s
Cannot get kernel name, error %d
Cannot get kernel name, error %d
Kill process %d
Kill process %d
Check processes in %d threads
Check processes in %d threads
Cannot find process %d
Cannot find process %d
Usage: %S [options]
Usage: %S [options]
-wmi - report about WMI entries
-wmi - report about WMI entries
-uem - check for Unknown Executable Memory
-uem - check for Unknown Executable Memory
-npo - dump RPC Named Pipes Owner
-npo - dump RPC Named Pipes Owner
-rdata - check .rdata sections too
-rdata - check .rdata sections too
-rpc - report about RPC interfaces
-rpc - report about RPC interfaces
DeriveKey
DeriveKey
NotifyChangeKey
NotifyChangeKey
EnumKeys
EnumKeys
IsAlgSupported
IsAlgSupported
FreeKey
FreeKey
DeleteKey
DeleteKey
FinalizeKey
FinalizeKey
SetKeyProperty
SetKeyProperty
CreatePersistedKey
CreatePersistedKey
OpenKey
OpenKey
OpenPrivateKey
OpenPrivateKey
ImportKey
ImportKey
ImportMasterKey
ImportMasterKey
GetKeyProperty
GetKeyProperty
GenerateSessionKeys
GenerateSessionKeys
GenerateMasterKey
GenerateMasterKey
ExportKey
ExportKey
CreateEphemeralKey
CreateEphemeralKey
ComputeEapKeyBlock
ComputeEapKeyBlock
ncrypt_hack::check_in_proc: cannot alloc %d bytes
ncrypt_hack::check_in_proc: cannot alloc %d bytes
GetKeyStorageInterface
GetKeyStorageInterface
Cannot load %s (copy of %s), error %d
Cannot load %s (copy of %s), error %d
Cannot load module %s, error %d
Cannot load module %s, error %d
Cannot read module %s import table
Cannot read module %s import table
NdisMRegisterMiniportDriver
NdisMRegisterMiniportDriver
resolve_minidrivers_list: bad addr of NdisMRegisterMiniportDriver
resolve_minidrivers_list: bad addr of NdisMRegisterMiniportDriver
NdisMRegisterMiniport
NdisMRegisterMiniport
resolve_minidrivers_list: cannot find NdisMRegisterMiniport
resolve_minidrivers_list: cannot find NdisMRegisterMiniport
resolve_minidrivers_list: bad addr of NdisMRegisterMiniport
resolve_minidrivers_list: bad addr of NdisMRegisterMiniport
resolve_miniports_list: cannot find NdisIMInitializeDeviceInstanceEx
resolve_miniports_list: cannot find NdisIMInitializeDeviceInstanceEx
resolve_miniports_list: bad addr of NdisIMInitializeDeviceInstanceEx
resolve_miniports_list: bad addr of NdisIMInitializeDeviceInstanceEx
OID_CO_TAPI_DONT_REPORT_DIGITS
OID_CO_TAPI_DONT_REPORT_DIGITS
OID_CO_TAPI_REPORT_DIGITS
OID_CO_TAPI_REPORT_DIGITS
OID_QOS_OPERATIONAL_PARAMETERS
OID_QOS_OPERATIONAL_PARAMETERS
OID_TCP_TASK_IPSEC_OFFLOAD_V2_ADD_SA_EX
OID_TCP_TASK_IPSEC_OFFLOAD_V2_ADD_SA_EX
OID_TCP_TASK_IPSEC_OFFLOAD_V2_UPDATE_SA
OID_TCP_TASK_IPSEC_OFFLOAD_V2_UPDATE_SA
OID_TCP_TASK_IPSEC_OFFLOAD_V2_DELETE_SA
OID_TCP_TASK_IPSEC_OFFLOAD_V2_DELETE_SA
OID_TCP_TASK_IPSEC_OFFLOAD_V2_ADD_SA
OID_TCP_TASK_IPSEC_OFFLOAD_V2_ADD_SA
OID_TCP_CONNECTION_OFFLOAD_PARAMETERS
OID_TCP_CONNECTION_OFFLOAD_PARAMETERS
OID_FFP_SUPPORT
OID_FFP_SUPPORT
OID_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIES
OID_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIES
OID_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIG
OID_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIG
OID_TCP_OFFLOAD_HARDWARE_CAPABILITIES
OID_TCP_OFFLOAD_HARDWARE_CAPABILITIES
OID_TCP_OFFLOAD_PARAMETERS
OID_TCP_OFFLOAD_PARAMETERS
OID_TCP_OFFLOAD_CURRENT_CONFIG
OID_TCP_OFFLOAD_CURRENT_CONFIG
OID_TCP6_OFFLOAD_STATS
OID_TCP6_OFFLOAD_STATS
OID_TCP4_OFFLOAD_STATS
OID_TCP4_OFFLOAD_STATS
OID_TCP_TASK_IPSEC_DELETE_UDPESP_SA
OID_TCP_TASK_IPSEC_DELETE_UDPESP_SA
OID_TCP_TASK_IPSEC_ADD_UDPESP_SA
OID_TCP_TASK_IPSEC_ADD_UDPESP_SA
OID_TCP_SAN_SUPPORT
OID_TCP_SAN_SUPPORT
OID_TCP_TASK_IPSEC_DELETE_SA
OID_TCP_TASK_IPSEC_DELETE_SA
OID_TCP_TASK_IPSEC_ADD_SA
OID_TCP_TASK_IPSEC_ADD_SA
OID_TCP_TASK_OFFLOAD
OID_TCP_TASK_OFFLOAD
OID_DOT11_SUPPORTED_DSSS_CHANNEL_LIST
OID_DOT11_SUPPORTED_DSSS_CHANNEL_LIST
OID_DOT11_SUPPORTED_OFDM_FREQUENCY_LIST
OID_DOT11_SUPPORTED_OFDM_FREQUENCY_LIST
OID_DOT11_QOS_TX_QUEUES_SUPPORTED
OID_DOT11_QOS_TX_QUEUES_SUPPORTED
OID_DOT11_AP_JOIN_REQUEST
OID_DOT11_AP_JOIN_REQUEST
OID_DOT11_HR_CCA_MODE_SUPPORTED
OID_DOT11_HR_CCA_MODE_SUPPORTED
OID_DOT11_FREQUENCY_BANDS_SUPPORTED
OID_DOT11_FREQUENCY_BANDS_SUPPORTED
OID_DOT11_SUPPORTED_DATA_RATES_VALUE
OID_DOT11_SUPPORTED_DATA_RATES_VALUE
OID_DOT11_SUPPORTED_RX_ANTENNA
OID_DOT11_SUPPORTED_RX_ANTENNA
OID_DOT11_SUPPORTED_TX_ANTENNA
OID_DOT11_SUPPORTED_TX_ANTENNA
OID_DOT11_REG_DOMAINS_SUPPORT_VALUE
OID_DOT11_REG_DOMAINS_SUPPORT_VALUE
OID_DOT11_CCA_MODE_SUPPORTED
OID_DOT11_CCA_MODE_SUPPORTED
OID_DOT11_SUPPORTED_POWER_LEVELS
OID_DOT11_SUPPORTED_POWER_LEVELS
OID_DOT11_DIVERSITY_SUPPORT
OID_DOT11_DIVERSITY_SUPPORT
OID_DOT11_SUPPORTED_PHY_TYPES
OID_DOT11_SUPPORTED_PHY_TYPES
OID_DOT11_OPERATIONAL_RATE_SET
OID_DOT11_OPERATIONAL_RATE_SET
OID_DOT11_JOIN_REQUEST
OID_DOT11_JOIN_REQUEST
OID_DOT11_CURRENT_OPERATION_MODE
OID_DOT11_CURRENT_OPERATION_MODE
OID_DOT11_OPERATION_MODE_CAPABILITY
OID_DOT11_OPERATION_MODE_CAPABILITY
OID_802_11_SUPPORTED_RATES
OID_802_11_SUPPORTED_RATES
OID_802_11_NETWORK_TYPES_SUPPORTED
OID_802_11_NETWORK_TYPES_SUPPORTED
OID_802_11_REMOVE_KEY
OID_802_11_REMOVE_KEY
OID_802_11_ADD_KEY
OID_802_11_ADD_KEY
OID_IRDA_SUPPORTED_SPEEDS
OID_IRDA_SUPPORTED_SPEEDS
OID_ATM_SUPPORTED_AAL_TYPES
OID_ATM_SUPPORTED_AAL_TYPES
OID_ATM_SUPPORTED_SERVICE_CATEGORY
OID_ATM_SUPPORTED_SERVICE_CATEGORY
OID_ATM_SUPPORTED_VC_RATES
OID_ATM_SUPPORTED_VC_RATES
OID_FDDI_PORT_ACTION
OID_FDDI_PORT_ACTION
OID_FDDI_PORT_HARDWARE_PRESENT
OID_FDDI_PORT_HARDWARE_PRESENT
OID_FDDI_PORT_LER_FLAG
OID_FDDI_PORT_LER_FLAG
OID_FDDI_PORT_PC_WITHHOLD
OID_FDDI_PORT_PC_WITHHOLD
OID_FDDI_PORT_PCM_STATE
OID_FDDI_PORT_PCM_STATE
OID_FDDI_PORT_CONNNECT_STATE
OID_FDDI_PORT_CONNNECT_STATE
OID_FDDI_PORT_LER_ALARM
OID_FDDI_PORT_LER_ALARM
OID_FDDI_PORT_LER_CUTOFF
OID_FDDI_PORT_LER_CUTOFF
OID_FDDI_PORT_LEM_CT
OID_FDDI_PORT_LEM_CT
OID_FDDI_PORT_LEM_REJECT_CT
OID_FDDI_PORT_LEM_REJECT_CT
OID_FDDI_PORT_LER_ESTIMATE
OID_FDDI_PORT_LER_ESTIMATE
OID_FDDI_PORT_LCT_FAIL_CT
OID_FDDI_PORT_LCT_FAIL_CT
OID_FDDI_PORT_EB_ERROR_CT
OID_FDDI_PORT_EB_ERROR_CT
OID_FDDI_PORT_PC_LS
OID_FDDI_PORT_PC_LS
OID_FDDI_PORT_BS_FLAG
OID_FDDI_PORT_BS_FLAG
OID_FDDI_PORT_MAINT_LS
OID_FDDI_PORT_MAINT_LS
OID_FDDI_PORT_INDEX
OID_FDDI_PORT_INDEX
OID_FDDI_PORT_CONNECTION_CAPABILITIES
OID_FDDI_PORT_CONNECTION_CAPABILITIES
OID_FDDI_PORT_PMD_CLASS
OID_FDDI_PORT_PMD_CLASS
OID_FDDI_PORT_MAC_LOOP_TIME
OID_FDDI_PORT_MAC_LOOP_TIME
OID_FDDI_PORT_AVAILABLE_PATHS
OID_FDDI_PORT_AVAILABLE_PATHS
OID_FDDI_PORT_MAC_PLACEMENT
OID_FDDI_PORT_MAC_PLACEMENT
OID_FDDI_PORT_REQUESTED_PATHS
OID_FDDI_PORT_REQUESTED_PATHS
OID_FDDI_PORT_CURRENT_PATH
OID_FDDI_PORT_CURRENT_PATH
OID_FDDI_PORT_MAC_INDICATED
OID_FDDI_PORT_MAC_INDICATED
OID_FDDI_PORT_CONNECTION_POLICIES
OID_FDDI_PORT_CONNECTION_POLICIES
OID_FDDI_PORT_NEIGHBOR_TYPE
OID_FDDI_PORT_NEIGHBOR_TYPE
OID_FDDI_PORT_MY_TYPE
OID_FDDI_PORT_MY_TYPE
OID_FDDI_MAC_DOWNSTREAM_PORT_TYPE
OID_FDDI_MAC_DOWNSTREAM_PORT_TYPE
OID_FDDI_SMT_MSG_TIME_STAMP
OID_FDDI_SMT_MSG_TIME_STAMP
OID_FDDI_SMT_BYPASS_PRESENT
OID_FDDI_SMT_BYPASS_PRESENT
OID_FDDI_SMT_MAC_INDEXES
OID_FDDI_SMT_MAC_INDEXES
OID_FDDI_SMT_PORT_INDEXES
OID_FDDI_SMT_PORT_INDEXES
OID_TCP_RSC_STATISTICS
OID_TCP_RSC_STATISTICS
OID_SWITCH_PORT_UPDATED
OID_SWITCH_PORT_UPDATED
OID_GEN_OPERATIONAL_STATUS
OID_GEN_OPERATIONAL_STATUS
OID_SWITCH_PORT_TEARDOWN
OID_SWITCH_PORT_TEARDOWN
OID_SWITCH_PORT_FEATURE_STATUS_QUERY
OID_SWITCH_PORT_FEATURE_STATUS_QUERY
OID_SWITCH_PORT_DELETE
OID_SWITCH_PORT_DELETE
OID_SWITCH_PORT_CREATE
OID_SWITCH_PORT_CREATE
OID_SWITCH_PORT_ARRAY
OID_SWITCH_PORT_ARRAY
OID_SWITCH_PORT_PROPERTY_ENUM
OID_SWITCH_PORT_PROPERTY_ENUM
OID_SWITCH_PORT_PROPERTY_DELETE
OID_SWITCH_PORT_PROPERTY_DELETE
OID_SWITCH_PORT_PROPERTY_UPDATE
OID_SWITCH_PORT_PROPERTY_UPDATE
OID_SWITCH_PORT_PROPERTY_ADD
OID_SWITCH_PORT_PROPERTY_ADD
OID_NIC_SWITCH_DELETE_VPORT
OID_NIC_SWITCH_DELETE_VPORT
OID_NIC_SWITCH_ENUM_VPORTS
OID_NIC_SWITCH_ENUM_VPORTS
OID_NIC_SWITCH_VPORT_PARAMETERS
OID_NIC_SWITCH_VPORT_PARAMETERS
OID_NIC_SWITCH_CREATE_VPORT
OID_NIC_SWITCH_CREATE_VPORT
OID_GEN_MINIPORT_RESTART_ATTRIBUTES
OID_GEN_MINIPORT_RESTART_ATTRIBUTES
OID_GEN_PORT_AUTHENTICATION_PARAMETERS
OID_GEN_PORT_AUTHENTICATION_PARAMETERS
OID_GEN_PORT_STATE
OID_GEN_PORT_STATE
OID_GEN_ENUMERATE_PORTS
OID_GEN_ENUMERATE_PORTS
OID_GEN_TRANSPORT_HEADER_OFFSET
OID_GEN_TRANSPORT_HEADER_OFFSET
OID_GEN_SUPPORTED_GUIDS
OID_GEN_SUPPORTED_GUIDS
OID_GEN_MEDIA_SUPPORTED
OID_GEN_MEDIA_SUPPORTED
OID_GEN_SUPPORTED_LIST
OID_GEN_SUPPORTED_LIST
Cannot read gWfpGlobal, readed %X bytes
Cannot read gWfpGlobal, readed %X bytes
Cannot read Wfp callout count, readed %X bytes
Cannot read Wfp callout count, readed %X bytes
Cannot read Wfp callouts, readed %X bytes
Cannot read Wfp callouts, readed %X bytes
Cannot read WFP index functions, readed %X bytes
Cannot read WFP index functions, readed %X bytes
iphlpapi.dll
iphlpapi.dll
%SystemRoot%\System32\iphlpapi.dll
%SystemRoot%\System32\iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
AllocateAndGetUdpExTableFromStack
GetExtendedTcpTable
GetExtendedTcpTable
GetExtendedUdpTable
GetExtendedUdpTable
Failed to snapshot TCP endpoints, error %d
Failed to snapshot TCP endpoints, error %d
Failed to snapshot UDP endpoints, error %d
Failed to snapshot UDP endpoints, error %d
Cannot alloc %d bytes for UDP extended table
Cannot alloc %d bytes for UDP extended table
Cannot alloc %d bytes for TCP extended table
Cannot alloc %d bytes for TCP extended table
ntdll_hack::try_hack: bad PE passed
ntdll_hack::try_hack: bad PE passed
ntdll_hack::try_hack: cannot find section .text
ntdll_hack::try_hack: cannot find section .text
ntdll_hack::try_hack: cannot read section .text
ntdll_hack::try_hack: cannot read section .text
ntdll_hack::try_hack: bad section passed
ntdll_hack::try_hack: bad section passed
ntdll_hack::try_hack: cannot read exports, error %d
ntdll_hack::try_hack: cannot read exports, error %d
%s channel hooks:
%s channel hooks:
ChannelHook[%d]: %p (%p - %s) %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
ChannelHook[%d]: %p (%p - %s) %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
ChannelHook[%d]: %p (%p) %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
ChannelHook[%d]: %p (%p) %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
MallocSpy: %p vtbl %p - %s
MallocSpy: %p vtbl %p - %s
webclient
webclient
msiexec32
msiexec32
msiexec
msiexec
tftp
tftp
ftp32
ftp32
cmd32
cmd32
ccmexec32
ccmexec32
ccmexec
ccmexec
chrome
chrome
opera
opera
firefox
firefox
Process PID %d raise dwwin PID %d
Process PID %d raise dwwin PID %d
Cannot alloc new process PID %d %S
Cannot alloc new process PID %d %S
Cannot open svchost process PID %d, error %d
Cannot open svchost process PID %d, error %d
proc_list::read: CreateToolhelp32Snapshot failed with error %d
proc_list::read: CreateToolhelp32Snapshot failed with error %d
PID %d Parent PID %d service {%S} %S
PID %d Parent PID %d service {%S} %S
PID %d Parent PID %d %S
PID %d Parent PID %d %S
PID %d Parent PID %d kind {%S} %S
PID %d Parent PID %d kind {%S} %S
read_service_exe_name(%S): cannot expand string %S
read_service_exe_name(%S): cannot expand string %S
ExWindowStationOpenProcedureCallout
ExWindowStationOpenProcedureCallout
ExWindowStationParseProcedureCallout
ExWindowStationParseProcedureCallout
ExWindowStationDeleteProcedureCallout
ExWindowStationDeleteProcedureCallout
ExWindowStationCloseProcedureCallout
ExWindowStationCloseProcedureCallout
ExWindowStationOkToCloseProcedureCallout
ExWindowStationOkToCloseProcedureCallout
read_w8_callout failed, len %d, returned %d bytes, error %d, ntstatus %X
read_w8_callout failed, len %d, returned %d bytes, error %d, ntstatus %X
read_w8_callout failed, len %d, returned %d bytes, error %d
read_w8_callout failed, len %d, returned %d bytes, error %d
PsWin32CallBack: %p %p %s
PsWin32CallBack: %p %p %s
check_callouts: cannot alloc %X bytes (size %d)
check_callouts: cannot alloc %X bytes (size %d)
check_callouts failed, error %d, status %X
check_callouts failed, error %d, status %X
check_callouts failed, error %d
check_callouts failed, error %d
Callouts (%d):
Callouts (%d):
%s: %p %s
%s: %p %s
ark_check_callbacks: cannot read size of callbacks list, error %d, ntstatus %X
ark_check_callbacks: cannot read size of callbacks list, error %d, ntstatus %X
ark_check_callbacks: cannot read size of callbacks list, error %d
ark_check_callbacks: cannot read size of callbacks list, error %d
ark_check_callbacks: cannot read %d bytes (readed %d), error %d, ntstatus %X
ark_check_callbacks: cannot read %d bytes (readed %d), error %d, ntstatus %X
ark_check_callbacks: cannot read %d bytes (readed %d), error %d
ark_check_callbacks: cannot read %d bytes (readed %d), error %d
CB: %S, total %X:
CB: %S, total %X:
%p (%s)
%p (%s)
check_shutdown_callbacks: cannot read size of callbacks list, error %d, ntstatus %X
check_shutdown_callbacks: cannot read size of callbacks list, error %d, ntstatus %X
check_shutdown_callbacks: cannot read size of callbacks list, error %d
check_shutdown_callbacks: cannot read size of callbacks list, error %d
check_shutdown_callbacks: cannot read callbacks list of %s, error %d, ntstatus %X
check_shutdown_callbacks: cannot read callbacks list of %s, error %d, ntstatus %X
check_shutdown_callbacks: cannot read callbacks list of %s, error %d
check_shutdown_callbacks: cannot read callbacks list of %s, error %d
%s - %d:
%s - %d:
FastIoUnlockAllByKey
FastIoUnlockAllByKey
MJ_CREATE_NAMED_PIPE
MJ_CREATE_NAMED_PIPE
%s!%s.%s patched by %s, addr %p
%s!%s.%s patched by %s, addr %p
%s!%s[%d] patched by %s, addr %p
%s!%s[%d] patched by %s, addr %p
Cannot open driver dumpfile %s, error %d
Cannot open driver dumpfile %s, error %d
Cannot open kernel dumpfile %s, error %d
Cannot open kernel dumpfile %s, error %d
Cannot read driver %s, error %d
Cannot read driver %s, error %d
hal.dll
hal.dll
Shadow SDT: %p, limit %X
Shadow SDT: %p, limit %X
win32k.sys
win32k.sys
Cannot relocate section %s.%s
Cannot relocate section %s.%s
Cannot alloc %X bytes for reading driver section %s.%s
Cannot alloc %X bytes for reading driver section %s.%s
Driver %s!%s has %X patched bytes !
Driver %s!%s has %X patched bytes !
.orig
.orig
.kmem
.kmem
Cannot read driver section %s.%s (flags %X) at %p size %X readed %X, error %d, ntstatus %X
Cannot read driver section %s.%s (flags %X) at %p size %X readed %X, error %d, ntstatus %X
Cannot read driver section %s.%s (flags %X) at %p size %X readed %X, error %d
Cannot read driver section %s.%s (flags %X) at %p size %X readed %X, error %d
Cannot read kernel %s, error %d
Cannot read kernel %s, error %d
ntoskrnl.exe
ntoskrnl.exe
Cannot alloc %X bytes for reading kernel sections
Cannot alloc %X bytes for reading kernel sections
Cannot relocate section %s
Cannot relocate section %s
KernelSection %s rva %X, size %X, 0x%X relocs has 0x%X patched bytes !
KernelSection %s rva %X, size %X, 0x%X relocs has 0x%X patched bytes !
Cannot read (whole) section %s (flags %X) at %p size %X (readed %X), error %d
Cannot read (whole) section %s (flags %X) at %p size %X (readed %X), error %d
\SystemRoot\system32\hal.dll
\SystemRoot\system32\hal.dll
\SystemRoot\system32\halapic.dll
\SystemRoot\system32\halapic.dll
\SystemRoot\system32\halmps.dll
\SystemRoot\system32\halmps.dll
\SystemRoot\system32\halacpi.dll
\SystemRoot\system32\halacpi.dll
\SystemRoot\system32\halaacpi.dll
\SystemRoot\system32\halaacpi.dll
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\halmacpi.dll
%SystemRoot%\System32\hal.dll
%SystemRoot%\System32\hal.dll
halapic.dll
halapic.dll
halmps.dll
halmps.dll
halacpi.dll
halacpi.dll
halaacpi.dll
halaacpi.dll
halmacpi.dll
halmacpi.dll
Driver %S DrvObj %p:
Driver %S DrvObj %p:
DriverUnload patched by %s, addr %p
DriverUnload patched by %s, addr %p
DriverStartIo patched by %s, addr %p
DriverStartIo patched by %s, addr %p
AddDevice patched by %s, addr %p
AddDevice patched by %s, addr %p
Handler %s patched by %s, addr %p
Handler %s patched by %s, addr %p
Handler %s patched, addr %p
Handler %s patched, addr %p
Handler %d patched by %s, addr %p
Handler %d patched by %s, addr %p
Handler %d patched, addr %p
Handler %d patched, addr %p
FastIOHandler %s patched by %s, addr %p
FastIOHandler %s patched by %s, addr %p
FastIOHandler %s patched, addr %p
FastIOHandler %s patched, addr %p
FastIOHandler %d patched by %s, addr %p
FastIOHandler %d patched by %s, addr %p
FastIOHandler %d patched, addr %p
FastIOHandler %d patched, addr %p
FS_FILTER_CALLBACKS %s patched by %s, addr %p
FS_FILTER_CALLBACKS %s patched by %s, addr %p
FS_FILTER_CALLBACKS %s patched, addr %p
FS_FILTER_CALLBACKS %s patched, addr %p
FS_FILTER_CALLBACKS %d patched by %s, addr %p
FS_FILTER_CALLBACKS %d patched by %s, addr %p
FS_FILTER_CALLBACKS %d patched, addr %p
FS_FILTER_CALLBACKS %d patched, addr %p
StartIo patched by %s, addr %p
StartIo patched by %s, addr %p
read_fsmjxxx(%S): cannot make full driver name
read_fsmjxxx(%S): cannot make full driver name
read_fsmjxxx(%S) failed, error %d, ntstatus %X
read_fsmjxxx(%S) failed, error %d, ntstatus %X
read_fsmjxxx(%S) failed, error %d
read_fsmjxxx(%S) failed, error %d
read_mjxxx(%s): cannot make full driver name
read_mjxxx(%s): cannot make full driver name
read_mjxxx(%S) failed, error %d, ntstatus %X
read_mjxxx(%S) failed, error %d, ntstatus %X
read_mjxxx(%S) failed, error %d
read_mjxxx(%S) failed, error %d
Cannot alloc %X bytes for driver %s EAT checking
Cannot alloc %X bytes for driver %s EAT checking
read_driver_eat %s failed, error %d, status %X
read_driver_eat %s failed, error %d, status %X
read_driver_eat %s failed, error %d
read_driver_eat %s failed, error %d
Export addr %s.%s patched by %s !
Export addr %s.%s patched by %s !
Export addr %s.%s patched !
Export addr %s.%s patched !
Export addr %s.%d patched by %s !
Export addr %s.%d patched by %s !
Export addr %s.%d patched!
Export addr %s.%d patched!
\hal.dll
\hal.dll
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\ndis.sys
ndis.sys
ndis.sys
drivers\ndis.sys
drivers\ndis.sys
\SystemRoot\system32\DRIVERS\tdi.sys
\SystemRoot\system32\DRIVERS\tdi.sys
tdi.sys
tdi.sys
drivers\tdi.sys
drivers\tdi.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
tcpip.sys
tcpip.sys
drivers\tcpip.sys
drivers\tcpip.sys
\SystemRoot\system32\DRIVERS\netio.sys
\SystemRoot\system32\DRIVERS\netio.sys
netio.sys
netio.sys
drivers\netio.sys
drivers\netio.sys
\SystemRoot\system32\DRIVERS\fltmgr.sys
\SystemRoot\system32\DRIVERS\fltmgr.sys
fltmgr.sys
fltmgr.sys
drivers\fltmgr.sys
drivers\fltmgr.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\ks.sys
ks.sys
ks.sys
drivers\ks.sys
drivers\ks.sys
\SystemRoot\system32\DRIVERS\dxg.sys
\SystemRoot\system32\DRIVERS\dxg.sys
drivers\dxg.sys
drivers\dxg.sys
\SystemRoot\system32\DRIVERS\dxgkrnl.sys
\SystemRoot\system32\DRIVERS\dxgkrnl.sys
drivers\dxgkrnl.sys
drivers\dxgkrnl.sys
\SystemRoot\system32\DRIVERS\watchdog.sys
\SystemRoot\system32\DRIVERS\watchdog.sys
drivers\watchdog.sys
drivers\watchdog.sys
\SystemRoot\system32\DRIVERS\ksecdd.sys
\SystemRoot\system32\DRIVERS\ksecdd.sys
ksecdd.sys
ksecdd.sys
drivers\ksecdd.sys
drivers\ksecdd.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\Ntfs.sys
ntfs.sys
ntfs.sys
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CLFS.SYS
CLFS.SYS
CLFS.SYS
\SystemRoot\system32\drivers\ataport.sys
\SystemRoot\system32\drivers\ataport.sys
ataport.sys
ataport.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\atapi.sys
atapi.sys
atapi.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\system32\drivers\peauth.sys
peauth.sys
peauth.sys
\SystemRoot\system32\drivers\WDFLDR.sys
\SystemRoot\system32\drivers\WDFLDR.sys
WDFLDR.sys
WDFLDR.sys
\SystemRoot\system32\drivers\usbstor.sys
\SystemRoot\system32\drivers\usbstor.sys
usbstor.sys
usbstor.sys
\SystemRoot\system32\drivers\usbd.sys
\SystemRoot\system32\drivers\usbd.sys
usbd.sys
usbd.sys
\SystemRoot\system32\drivers\USBPORT.sys
\SystemRoot\system32\drivers\USBPORT.sys
USBPORT.sys
USBPORT.sys
\SystemRoot\system32\drivers\usbohci.sys
\SystemRoot\system32\drivers\usbohci.sys
usbohci.sys
usbohci.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\usbehci.sys
usbehci.sys
usbehci.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\system32\drivers\usbhub.sys
usbhub.sys
usbhub.sys
\SystemRoot\system32\drivers\usbccgp.sys
\SystemRoot\system32\drivers\usbccgp.sys
usbccgp.sys
usbccgp.sys
\SystemRoot\system32\drivers\discache.sys
\SystemRoot\system32\drivers\discache.sys
discache.sys
discache.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\drivers\termdd.sys
termdd.sys
termdd.sys
\SystemRoot\system32\drivers\rdppr.sys
\SystemRoot\system32\drivers\rdppr.sys
rdppr.sys
rdppr.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\system32\drivers\mssmbios.sys
mssmbios.sys
mssmbios.sys
\SystemRoot\system32\drivers\1394BUS.SYS
\SystemRoot\system32\drivers\1394BUS.SYS
1394BUS.SYS
1394BUS.SYS
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\BATTC.SYS
BATTC.SYS
BATTC.SYS
\SystemRoot\system32\drivers\bthport.sys
\SystemRoot\system32\drivers\bthport.sys
bthport.sys
bthport.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\drmk.sys
drmk.sys
drmk.sys
\SystemRoot\system32\drivers\HIDPARSE.SYS
\SystemRoot\system32\drivers\HIDPARSE.SYS
HIDPARSE.SYS
HIDPARSE.SYS
\SystemRoot\system32\drivers\HIDCLASS.SYS
\SystemRoot\system32\drivers\HIDCLASS.SYS
HIDCLASS.SYS
HIDCLASS.SYS
\SystemRoot\system32\drivers\msiscsi.sys
\SystemRoot\system32\drivers\msiscsi.sys
msiscsi.sys
msiscsi.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\PCIIDEX.SYS
PCIIDEX.SYS
PCIIDEX.SYS
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\portcls.sys
portcls.sys
portcls.sys
\SystemRoot\system32\drivers\smsmdm.sys
\SystemRoot\system32\drivers\smsmdm.sys
smsmdm.sys
smsmdm.sys
\SystemRoot\system32\drivers\STREAM.SYS
\SystemRoot\system32\drivers\STREAM.SYS
STREAM.SYS
STREAM.SYS
\SystemRoot\system32\drivers\vga.sys
\SystemRoot\system32\drivers\vga.sys
vga.sys
vga.sys
\SystemRoot\system32\drivers\VIDEOPRT.SYS
\SystemRoot\system32\drivers\VIDEOPRT.SYS
VIDEOPRT.SYS
VIDEOPRT.SYS
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\vmstorfl.sys
vmstorfl.sys
vmstorfl.sys
\SystemRoot\system32\drivers\Dxapi.sys
\SystemRoot\system32\drivers\Dxapi.sys
Dxapi.sys
Dxapi.sys
\SystemRoot\system32\drivers\dxgthk.sys
\SystemRoot\system32\drivers\dxgthk.sys
dxgthk.sys
dxgthk.sys
\SystemRoot\system32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\dxgmms1.sys
dxgmms1.sys
dxgmms1.sys
\SystemRoot\system32\drivers\spsys.sys
\SystemRoot\system32\drivers\spsys.sys
spsys.sys
spsys.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\drivers\winhv.sys
winhv.sys
winhv.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\HdAudio.sys
HdAudio.sys
HdAudio.sys
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\cdd.dll
cdd.dll
cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\System32\ATMFD.DLL
ATMFD.DLL
ATMFD.DLL
\SystemRoot\System32\RDPDD.dll
\SystemRoot\System32\RDPDD.dll
RDPDD.dll
RDPDD.dll
\SystemRoot\system32\drivers\vwifibus.sys
\SystemRoot\system32\drivers\vwifibus.sys
vwifibus.sys
vwifibus.sys
\SystemRoot\system32\drivers\nwifi.sys
\SystemRoot\system32\drivers\nwifi.sys
nwifi.sys
nwifi.sys
\SystemRoot\system32\drivers\vwififlt.sys
\SystemRoot\system32\drivers\vwififlt.sys
vwififlt.sys
vwififlt.sys
\SystemRoot\system32\drivers\wfplwf.sys
\SystemRoot\system32\drivers\wfplwf.sys
wfplwf.sys
wfplwf.sys
\SystemRoot\system32\drivers\wfplwfs.sys
\SystemRoot\system32\drivers\wfplwfs.sys
wfplwfs.sys
wfplwfs.sys
\SystemRoot\system32\drivers\tmtdi.sys
\SystemRoot\system32\drivers\tmtdi.sys
tmtdi.sys
tmtdi.sys
\SystemRoot\system32\drivers\netvsc60.sys
\SystemRoot\system32\drivers\netvsc60.sys
netvsc60.sys
netvsc60.sys
\SystemRoot\system32\drivers\mslldp.sys
\SystemRoot\system32\drivers\mslldp.sys
mslldp.sys
mslldp.sys
\SystemRoot\system32\drivers\netvsc63.sys
\SystemRoot\system32\drivers\netvsc63.sys
netvsc63.sys
netvsc63.sys
\SystemRoot\system32\drivers\ndiscap.sys
\SystemRoot\system32\drivers\ndiscap.sys
ndiscap.sys
ndiscap.sys
\SystemRoot\system32\drivers\agilevpn.sys
\SystemRoot\system32\drivers\agilevpn.sys
agilevpn.sys
agilevpn.sys
\SystemRoot\system32\drivers\asyncmac.sys
\SystemRoot\system32\drivers\asyncmac.sys
asyncmac.sys
asyncmac.sys
\SystemRoot\system32\drivers\mpsdrv.sys
\SystemRoot\system32\drivers\mpsdrv.sys
mpsdrv.sys
mpsdrv.sys
\SystemRoot\system32\drivers\rspndr.sys
\SystemRoot\system32\drivers\rspndr.sys
rspndr.sys
rspndr.sys
\SystemRoot\system32\drivers\ndisuio.sys
\SystemRoot\system32\drivers\ndisuio.sys
ndisuio.sys
ndisuio.sys
\SystemRoot\system32\drivers\lltdio.sys
\SystemRoot\system32\drivers\lltdio.sys
lltdio.sys
lltdio.sys
\SystemRoot\system32\drivers\NDProxy.sys
\SystemRoot\system32\drivers\NDProxy.sys
NDProxy.sys
NDProxy.sys
\SystemRoot\system32\drivers\raspppoe.sys
\SystemRoot\system32\drivers\raspppoe.sys
raspppoe.sys
raspppoe.sys
\SystemRoot\system32\drivers\ndiswan.sys
\SystemRoot\system32\drivers\ndiswan.sys
ndiswan.sys
ndiswan.sys
\SystemRoot\system32\drivers\wanarp.sys
\SystemRoot\system32\drivers\wanarp.sys
wanarp.sys
wanarp.sys
\SystemRoot\system32\drivers\bthpan.sys
\SystemRoot\system32\drivers\bthpan.sys
bthpan.sys
bthpan.sys
\SystemRoot\system32\drivers\rassstp.sys
\SystemRoot\system32\drivers\rassstp.sys
rassstp.sys
rassstp.sys
\SystemRoot\system32\drivers\raspptp.sys
\SystemRoot\system32\drivers\raspptp.sys
raspptp.sys
raspptp.sys
\SystemRoot\system32\drivers\rasl2tp.sys
\SystemRoot\system32\drivers\rasl2tp.sys
rasl2tp.sys
rasl2tp.sys
\SystemRoot\system32\drivers\rasacd.sys
\SystemRoot\system32\drivers\rasacd.sys
rasacd.sys
rasacd.sys
\SystemRoot\system32\drivers\tunnel.sys
\SystemRoot\system32\drivers\tunnel.sys
tunnel.sys
tunnel.sys
\SystemRoot\system32\drivers\tunmp.sys
\SystemRoot\system32\drivers\tunmp.sys
tunmp.sys
tunmp.sys
\SystemRoot\system32\drivers\pacer.sys
\SystemRoot\system32\drivers\pacer.sys
pacer.sys
pacer.sys
\SystemRoot\system32\drivers\NDISTAPI.SYS
\SystemRoot\system32\drivers\NDISTAPI.SYS
NDISTAPI.SYS
NDISTAPI.SYS
\SystemRoot\system32\drivers\msgpc.sys
\SystemRoot\system32\drivers\msgpc.sys
msgpc.sys
msgpc.sys
\SystemRoot\system32\drivers\partmgr.sys
\SystemRoot\system32\drivers\partmgr.sys
partmgr.sys
partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
volmgr.sys
volmgr.sys
\SystemRoot\system32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\volmgrx.sys
volmgrx.sys
volmgrx.sys
\SystemRoot\system32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\mountmgr.sys
mountmgr.sys
mountmgr.sys
\SystemRoot\system32\drivers\iaStor.sys
\SystemRoot\system32\drivers\iaStor.sys
iaStor.sys
iaStor.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\system32\drivers\volsnap.sys
volsnap.sys
volsnap.sys
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\ACPI.sys
acpi.sys
acpi.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
WppRecorder.sys
WppRecorder.sys
\SystemRoot\System32\Drivers\Mouclass.sys
\SystemRoot\System32\Drivers\Mouclass.sys
Mouclass.sys
Mouclass.sys
\SystemRoot\System32\Drivers\kbdclass.sys
\SystemRoot\System32\Drivers\kbdclass.sys
kbdclass.sys
kbdclass.sys
\SystemRoot\System32\Drivers\Fastfat.SYS
\SystemRoot\System32\Drivers\Fastfat.SYS
Fastfat.sys
Fastfat.sys
\SystemRoot\System32\Drivers\bowser.sys
\SystemRoot\System32\Drivers\bowser.sys
bowser.sys
bowser.sys
\SystemRoot\System32\Drivers\rdbss.sys
\SystemRoot\System32\Drivers\rdbss.sys
rdbss.sys
rdbss.sys
\SystemRoot\System32\Drivers\msfs.sys
\SystemRoot\System32\Drivers\msfs.sys
msfs.sys
msfs.sys
\SystemRoot\System32\Drivers\NetBIOS.sys
\SystemRoot\System32\Drivers\NetBIOS.sys
NetBIOS.sys
NetBIOS.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\Drivers\mup.sys
mup.sys
mup.sys
\SystemRoot\System32\Drivers\dfs.sys
\SystemRoot\System32\Drivers\dfs.sys
dfs.sys
dfs.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\System32\Drivers\dfsc.sys
dfsc.sys
dfsc.sys
\SystemRoot\System32\Drivers\npfs.SYS
\SystemRoot\System32\Drivers\npfs.SYS
npfs.sys
npfs.sys
\SystemRoot\System32\Drivers\luafv.SYS
\SystemRoot\System32\Drivers\luafv.SYS
luafv.sys
luafv.sys
\SystemRoot\System32\Drivers\MRxSmb.SYS
\SystemRoot\System32\Drivers\MRxSmb.SYS
MRxSmb.sys
MRxSmb.sys
\SystemRoot\System32\Drivers\MRxSmb10.SYS
\SystemRoot\System32\Drivers\MRxSmb10.SYS
MRxSmb10.sys
MRxSmb10.sys
\SystemRoot\System32\Drivers\MRxSmb20.SYS
\SystemRoot\System32\Drivers\MRxSmb20.SYS
MRxSmb20.sys
MRxSmb20.sys
\SystemRoot\System32\Drivers\MRxDAV.SYS
\SystemRoot\System32\Drivers\MRxDAV.SYS
MRxDAV.sys
MRxDAV.sys
\SystemRoot\system32\Drivers\fltmgr.sys
\SystemRoot\system32\Drivers\fltmgr.sys
\SystemRoot\system32\Drivers\TDI.SYS
\SystemRoot\system32\Drivers\TDI.SYS
\SystemRoot\system32\Drivers\tdx.sys
\SystemRoot\system32\Drivers\tdx.sys
\SystemRoot\system32\Drivers\ipfltdrv.sys
\SystemRoot\system32\Drivers\ipfltdrv.sys
\SystemRoot\system32\Drivers\tcpip.sys
\SystemRoot\system32\Drivers\tcpip.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\System32\drivers\afd.sys
afd.sys
afd.sys
\SystemRoot\System32\drivers\netbt.sys
\SystemRoot\System32\drivers\netbt.sys
\SystemRoot\System32\drivers\NETIO.sys
\SystemRoot\System32\drivers\NETIO.sys
\SystemRoot\System32\drivers\srv.sys
\SystemRoot\System32\drivers\srv.sys
srv.sys
srv.sys
\SystemRoot\System32\drivers\srv2.sys
\SystemRoot\System32\drivers\srv2.sys
srv2.sys
srv2.sys
\SystemRoot\System32\drivers\srvnet.sys
\SystemRoot\System32\drivers\srvnet.sys
\SystemRoot\System32\drivers\sr.sys
\SystemRoot\System32\drivers\sr.sys
sr.sys
sr.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\http.sys
\SystemRoot\System32\drivers\http.sys
http.sys
http.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\msrpc.sys
\SystemRoot\system32\DRIVERS\msrpc.sys
msrpc.sys
msrpc.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\disk.sys
disk.sys
disk.sys
\SystemRoot\system32\DRIVERS\ftdisk.sys
\SystemRoot\system32\DRIVERS\ftdisk.sys
ftdisk.sys
ftdisk.sys
\SystemRoot\system32\DRIVERS\Storport.SYS
\SystemRoot\system32\DRIVERS\Storport.SYS
Storport.SYS
Storport.SYS
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
CLASSPNP.SYS
CLASSPNP.SYS
\SystemRoot\system32\Drivers\ks.sys
\SystemRoot\system32\Drivers\ks.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\ksecdd.sys
ksecdd.SYS
ksecdd.SYS
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\kdcom.dll
kdcom.dll
kdcom.dll
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\Drivers\cng.sys
cng.sys
cng.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\PSHED.dll
PSHED.dll
PSHED.dll
\SystemRoot\system32\CI.dll
\SystemRoot\system32\CI.dll
CI.dll
CI.dll
\SystemRoot\system32\DRIVERS\WMILIB.SYS
\SystemRoot\system32\DRIVERS\WMILIB.SYS
wmilib.sys
wmilib.sys
Cannot find %s for IAT resolving of %s
Cannot find %s for IAT resolving of %s
Cannot alloc %X bytes for drivers IAT checking
Cannot alloc %X bytes for drivers IAT checking
Cannot find %s import %s.%s
Cannot find %s import %s.%s
Cannot find %s import %s.%d
Cannot find %s import %s.%d
IAT %s %s.%s patched, addr %p
IAT %s %s.%s patched, addr %p
IAT %s %s.%d patched, addr %p
IAT %s %s.%d patched, addr %p
IAT %s %s.%s patched by %s, addr %p
IAT %s %s.%s patched by %s, addr %p
IAT %s %s.%d patched by %s, addr %p
IAT %s %s.%d patched by %s, addr %p
%s has %d patched IAT entries (total %d)
%s has %d patched IAT entries (total %d)
reading of IAT %s failed, readed %X, actual IAT size %X, error %d
reading of IAT %s failed, readed %X, actual IAT size %X, error %d
check_exts count failed, error %d, ntstatus %X
check_exts count failed, error %d, ntstatus %X
check_exts count failed, error %d
check_exts count failed, error %d
check_exts: cannot alloc %X bytes
check_exts: cannot alloc %X bytes
check_exts failed, error %d, ntstatus %X
check_exts failed, error %d, ntstatus %X
check_exts failed, error %d
check_exts failed, error %d
Ext[%X]:
Ext[%X]:
Handler1: %p %s
Handler1: %p %s
Handler2: %p %s
Handler2: %p %s
Handler3: %p %s
Handler3: %p %s
Table: %X items %p %s
Table: %X items %p %s
Item[%X]: %p %s
Item[%X]: %p %s
IRP_MJ_CREATE_NAMED_PIPE
IRP_MJ_CREATE_NAMED_PIPE
Unknown fltmgr: FrameList %X FilterSize %X cbn %X
Unknown fltmgr: FrameList %X FilterSize %X cbn %X
Unknown fltmgr: FrameList %X FilterSize %X
Unknown fltmgr: FrameList %X FilterSize %X
FltMgr: index %d
FltMgr: index %d
FRAME[%d] %p
FRAME[%d] %p
%s: %p
%s: %p
NormalizeNameComponent: %p %s
NormalizeNameComponent: %p %s
NormalizeContextCleanup: %p %s
NormalizeContextCleanup: %p %s
PreOperation: %p %s
PreOperation: %p %s
PostOperation: %p %s
PostOperation: %p %s
check_ks: cannot read size of ks list, error %d, ntstatus %X
check_ks: cannot read size of ks list, error %d, ntstatus %X
check_ks: cannot read size of ks list, error %d
check_ks: cannot read size of ks list, error %d
ks count: %X
ks count: %X
check_ks: cannot alloc %X bytes
check_ks: cannot alloc %X bytes
check_ks: cannot read ks list, error %d, ntstatus %X
check_ks: cannot read ks list, error %d, ntstatus %X
check_ks: cannot read ks list, error %d
check_ks: cannot read ks list, error %d
ks[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
ks[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
ChangeAccountPassword
ChangeAccountPassword
ImportSecurityContext
ImportSecurityContext
ExportSecurityContext
ExportSecurityContext
gKsecpBCryptExtension: %p %s
gKsecpBCryptExtension: %p %s
gKsecpSslExtension: %p %s
gKsecpSslExtension: %p %s
SecTable.%s patched %p %s
SecTable.%s patched %p %s
dxg.sys
dxg.sys
dxgkrnl.sys
dxgkrnl.sys
Win32kCallout: %p %s
Win32kCallout: %p %s
SessionStartCallout: %p %s
SessionStartCallout: %p %s
KTIMER %p DPC %p DefRoutine %p %s
KTIMER %p DPC %p DefRoutine %p %s
Cannot find KPRCB.DpcRoutineActive
Cannot find KPRCB.DpcRoutineActive
Unknown KPRCB: DpcRoutineActive %X WorkerRoutine %X
Unknown KPRCB: DpcRoutineActive %X WorkerRoutine %X
Unknown KPRCB: DpcRoutineActive %X
Unknown KPRCB: DpcRoutineActive %X
Processor %d:
Processor %d:
KTIMERS[%d]: %X
KTIMERS[%d]: %X
Patched %s %X by %s
Patched %s %X by %s
Patched ord.%d %X by %s
Patched ord.%d %X by %s
Patched %s %X
Patched %s %X
Patched ord.%d %X
Patched ord.%d %X
Patched %s by %s
Patched %s by %s
Patched ord.%d by %s
Patched ord.%d by %s
Patched %s
Patched %s
Patched ord.%d
Patched ord.%d
Exception %X occured during EAT checking of %s
Exception %X occured during EAT checking of %s
check_module_iat(%s) - cannot find exports for %s
check_module_iat(%s) - cannot find exports for %s
check_module_iat(%s): zeroed ImportLookUp, cannot check import
check_module_iat(%s): zeroed ImportLookUp, cannot check import
Cannot find ordinal %X in module %s (%s) in import table of %s
Cannot find ordinal %X in module %s (%s) in import table of %s
Cannot find symbol %s in module %s (%s) in import table of %s
Cannot find symbol %s in module %s (%s) in import table of %s
(%s) %s.%s hooked in %s: my IAT %p, must be %p
(%s) %s.%s hooked in %s: my IAT %p, must be %p
(%s) %s.%d hooked in %s: my IAT %p, must be %p
(%s) %s.%d hooked in %s: my IAT %p, must be %p
apfn %s patched by %s, addr %p
apfn %s patched by %s, addr %p
apfn[%d] patched by %s, addr %p
apfn[%d] patched by %s, addr %p
apfn %s patched, addr %p
apfn %s patched, addr %p
apfn[%d] patched, addr %p
apfn[%d] patched, addr %p
%s%s!%s patched by %s, addr %p
%s%s!%s patched by %s, addr %p
%s%s![%d] patched by %s, addr %p
%s%s![%d] patched by %s, addr %p
%s%s!%s patched, addr %p
%s%s!%s patched, addr %p
%s%s![%d] patched, addr %p
%s%s![%d] patched, addr %p
LSA SP %s has %d patched functions in SECPKG_FUNCTION_TABLE:
LSA SP %s has %d patched functions in SECPKG_FUNCTION_TABLE:
PID %d: LSA SP %s has %d patched functions in SECPKG_USER_FUNCTION_TABLE:
PID %d: LSA SP %s has %d patched functions in SECPKG_USER_FUNCTION_TABLE:
PID %d: LSA SP %s has %d patched functions in CallPackageDispatch:
PID %d: LSA SP %s has %d patched functions in CallPackageDispatch:
ole32 hooked by %s
ole32 hooked by %s
Cannot relocate section %s!%s
Cannot relocate section %s!%s
Exception %X occured on checking %s!%s
Exception %X occured on checking %s!%s
Module %s!%s has %X patched bytes !
Module %s!%s has %X patched bytes !
Exception %X occured on check_module_iat(%s)
Exception %X occured on check_module_iat(%s)
MyModule: %p %s
MyModule: %p %s
%SystemRoot%\System32\ncrypt.dll
%SystemRoot%\System32\ncrypt.dll
%SystemRoot%\System32\ntdsa.dll
%SystemRoot%\System32\ntdsa.dll
%SystemRoot%\System32\kernelbase.dll
%SystemRoot%\System32\kernelbase.dll
%SystemRoot%\System32\kernel32.dll
%SystemRoot%\System32\kernel32.dll
%SystemRoot%\System32\user32.dll
%SystemRoot%\System32\user32.dll
%SystemRoot%\System32\umpnpmgr.dll
%SystemRoot%\System32\umpnpmgr.dll
%SystemRoot%\System32\combase.dll
%SystemRoot%\System32\combase.dll
%SystemRoot%\System32\ole32.dll
%SystemRoot%\System32\ole32.dll
%SystemRoot%\System32\imm32.dll
%SystemRoot%\System32\imm32.dll
%SystemRoot%\System32\rpcrt4.dll
%SystemRoot%\System32\rpcrt4.dll
%SystemRoot%\System32\mswsock.dll
%SystemRoot%\System32\mswsock.dll
%SystemRoot%\System32\advapi32.dll
%SystemRoot%\System32\advapi32.dll
%SystemRoot%\System32\cryptbase.dll
%SystemRoot%\System32\cryptbase.dll
%SystemRoot%\System32\apisetschema.dll
%SystemRoot%\System32\apisetschema.dll
read_ndis_oid_handlers failed, returned %d bytes, error %d, ntstatus %X
read_ndis_oid_handlers failed, returned %d bytes, error %d, ntstatus %X
read_ndis_oid_handlers failed, returned %d bytes, error %d
read_ndis_oid_handlers failed, returned %d bytes, error %d
[%X] %s: post %p %s
[%X] %s: post %p %s
[%X] %s: pre %p %s
[%X] %s: pre %p %s
[%X] %s: pre %p (%s) post %p (%s)
[%X] %s: pre %p (%s) post %p (%s)
[%X] %X: post %p %s
[%X] %X: post %p %s
[%X] %X: pre %p %s
[%X] %X: pre %p %s
[%X] %X: pre %p (%s) post %p (%s)
[%X] %X: pre %p (%s) post %p (%s)
read_tcp_off_handlers failed, returned %d bytes, error %d, ntstatus %X
read_tcp_off_handlers failed, returned %d bytes, error %d, ntstatus %X
read_tcp_off_handlers failed, returned %d bytes, error %d
read_tcp_off_handlers failed, returned %d bytes, error %d
TcpOfflineHandlers:
TcpOfflineHandlers:
TcpOffloadEventIndicate: %p %s
TcpOffloadEventIndicate: %p %s
TcpOffloadReceiveIndicate: %p %s
TcpOffloadReceiveIndicate: %p %s
TcpOffloadSendComplete: %p %s
TcpOffloadSendComplete: %p %s
TcpOffloadReceiveComplete: %p %s
TcpOffloadReceiveComplete: %p %s
TcpOffloadDisconnectComplete: %p %s
TcpOffloadDisconnectComplete: %p %s
TcpOffloadForwardComplete: %p %s
TcpOffloadForwardComplete: %p %s
Cannot alloc %X bytes from reading filter block
Cannot alloc %X bytes from reading filter block
read_ndis_filter_block: len %d, returned %d bytes, error %d, ntstatus %X
read_ndis_filter_block: len %d, returned %d bytes, error %d, ntstatus %X
read_ndis_filter_block: len %d, returned %d bytes, error %d
read_ndis_filter_block: len %d, returned %d bytes, error %d
check_ndis - reading of TDI callback failed, error %d, ntstatus %X
check_ndis - reading of TDI callback failed, error %d, ntstatus %X
check_ndis - reading of TDI callback failed, error %d
check_ndis - reading of TDI callback failed, error %d
check_ndis - reading of TDI PnP handler failed, error %d, ntstatus %X
check_ndis - reading of TDI PnP handler failed, error %d, ntstatus %X
check_ndis - reading of TDI PnP handler failed, error %d
check_ndis - reading of TDI PnP handler failed, error %d
TDI callback %p patched by %s
TDI callback %p patched by %s
TDI PnP handler %p patched by %s
TDI PnP handler %p patched by %s
check_ndis - reading of providers count failed, error %d, ntstatus %X
check_ndis - reading of providers count failed, error %d, ntstatus %X
check_ndis - reading of providers count failed, error %d
check_ndis - reading of providers count failed, error %d
check_ndis: %d providers
check_ndis: %d providers
check_ndis: cannot alloc %X bytes
check_ndis: cannot alloc %X bytes
Cannot store provider_block %p (%d)
Cannot store provider_block %p (%d)
check_ndis: stored %d provider_blocks
check_ndis: stored %d provider_blocks
check_ndis - reading of interfaces count failed, error %d, ntstatus %X
check_ndis - reading of interfaces count failed, error %d, ntstatus %X
check_ndis - reading of interfaces count failed, error %d
check_ndis - reading of interfaces count failed, error %d
check_ndis: %d interfaces, size of miniport %X
check_ndis: %d interfaces, size of miniport %X
Interface[%d]:
Interface[%d]:
check_ndis - reading of protocols count failed, error %d, ntstatus %X
check_ndis - reading of protocols count failed, error %d, ntstatus %X
check_ndis - reading of protocols count failed, error %d
check_ndis - reading of protocols count failed, error %d
check_ndis: %d protocols, size of protocol %X
check_ndis: %d protocols, size of protocol %X
check_ndis: stored %d protocols
check_ndis: stored %d protocols
check_ndis - reading of minidrivers count failed, error %d, ntstatus %X
check_ndis - reading of minidrivers count failed, error %d, ntstatus %X
check_ndis - reading of minidrivers count failed, error %d
check_ndis - reading of minidrivers count failed, error %d
check_ndis: %d minidrivers, size of minidriver %X, sizeof(ndis50) %X, sizeof(ndis52) %X
check_ndis: %d minidrivers, size of minidriver %X, sizeof(ndis50) %X, sizeof(ndis52) %X
Cannot store minidriver %d (%p)
Cannot store minidriver %d (%p)
Stored %d mini-drivers
Stored %d mini-drivers
check_ndis - reading of miniports count failed, error %d, ntstatus %X
check_ndis - reading of miniports count failed, error %d, ntstatus %X
check_ndis - reading of miniports count failed, error %d
check_ndis - reading of miniports count failed, error %d
check_ndis: %d miniports, size of miniport %X
check_ndis: %d miniports, size of miniport %X
check_ndis: read %d miniports, total %X
check_ndis: read %d miniports, total %X
Miniport[%d] %p:
Miniport[%d] %p:
check_ndis: stored %d miniports, sizeof(miniport_block_w7) %X
check_ndis: stored %d miniports, sizeof(miniport_block_w7) %X
check_ndis - reading of open_blocks count failed, error %d, ntstatus %X
check_ndis - reading of open_blocks count failed, error %d, ntstatus %X
check_ndis - reading of open_blocks count failed, error %d
check_ndis - reading of open_blocks count failed, error %d
check_ndis: %d open_blocks, size of open_block %X
check_ndis: %d open_blocks, size of open_block %X
check_ndis: read %d open_blocks, total %X
check_ndis: read %d open_blocks, total %X
Open_Block[%d]:
Open_Block[%d]:
Cannot store open_block %p (%d)
Cannot store open_block %p (%d)
check_ndis: stored %d open_blocks
check_ndis: stored %d open_blocks
check_ndis - reading of filter_drivers count failed, error %d, ntstatus %X
check_ndis - reading of filter_drivers count failed, error %d, ntstatus %X
check_ndis - reading of filter_drivers count failed, error %d
check_ndis - reading of filter_drivers count failed, error %d
check_ndis: %d filter_drivers, size of open_block %X
check_ndis: %d filter_drivers, size of open_block %X
check_ndis: read %d filter_drivers, total %X
check_ndis: read %d filter_drivers, total %X
FilterDriver[%d]:
FilterDriver[%d]:
check_ndis: stored %d filter_drivers, %d filter_blocks
check_ndis: stored %d filter_drivers, %d filter_blocks
Passive
Passive
read_punicode_string failed, len %d, returned %d bytes, error %d, ntstatus %X
read_punicode_string failed, len %d, returned %d bytes, error %d, ntstatus %X
read_punicode_string failed, len %d, returned %d bytes, error %d
read_punicode_string failed, len %d, returned %d bytes, error %d
Cannot read NDIS_MINIPORT_INTERRUPT %p
Cannot read NDIS_MINIPORT_INTERRUPT %p
NDIS_MINIPORT_INTERRUPT:
NDIS_MINIPORT_INTERRUPT:
MiniportIsr: %p %s
MiniportIsr: %p %s
MiniportDpc: %p %s
MiniportDpc: %p %s
Cannot read NDIS_MINIPORT_INTERRUPT_CHARACTERISTICS %p
Cannot read NDIS_MINIPORT_INTERRUPT_CHARACTERISTICS %p
NDIS_MINIPORT_INTERRUPT_CHARACTERISTICS:
NDIS_MINIPORT_INTERRUPT_CHARACTERISTICS:
InterruptHandler: %p %s
InterruptHandler: %p %s
InterruptDpcHandler: %p %s
InterruptDpcHandler: %p %s
DisableInterruptHandler: %p %s
DisableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
MessageInterruptHandler: %p %s
MessageInterruptHandler: %p %s
MessageInterruptDpcHandler: %p %s
MessageInterruptDpcHandler: %p %s
DisableMessageInterruptHandler: %p %s
DisableMessageInterruptHandler: %p %s
EnableMessageInterruptHandler: %p %s
EnableMessageInterruptHandler: %p %s
MiniportIsr: %p %s
MiniportIsr: %p %s
MiniportDpc: %p %s
MiniportDpc: %p %s
MiniportMessageIsr: %p %s
MiniportMessageIsr: %p %s
MiniportMessageInterruptDpc: %p %s
MiniportMessageInterruptDpc: %p %s
MiniportIsr: %p %s
MiniportIsr: %p %s
MiniportDpc: %p %s
MiniportDpc: %p %s
MiniportEnableInterrupt: %p %s
MiniportEnableInterrupt: %p %s
MiniportDisableInterrupt: %p %s
MiniportDisableInterrupt: %p %s
MiniportMessageIsr: %p %s
MiniportMessageIsr: %p %s
MiniportMessageInterruptDpc: %p %s
MiniportMessageInterruptDpc: %p %s
MiniportDisableMessageInterrupt: %p %s
MiniportDisableMessageInterrupt: %p %s
MiniportEnableMessageInterrupt: %p %s
MiniportEnableMessageInterrupt: %p %s
NDIS Protocol[%d]: %S
NDIS Protocol[%d]: %S
MajorNdisVersion %d
MajorNdisVersion %d
MinorNdisVersion %d
MinorNdisVersion %d
Flags %X
Flags %X
OpenAdapterCompleteHandler: %p %s
OpenAdapterCompleteHandler: %p %s
CloseAdapterCompleteHandler: %p %s
CloseAdapterCompleteHandler: %p %s
SendCompleteHandler: %p %s
SendCompleteHandler: %p %s
TransferDataCompleteHandler: %p %s
TransferDataCompleteHandler: %p %s
ResetCompleteHandler: %p %s
ResetCompleteHandler: %p %s
RequestCompleteHandler: %p %s
RequestCompleteHandler: %p %s
ReceiveHandler: %p %s
ReceiveHandler: %p %s
ReceiveCompleteHandler: %p %s
ReceiveCompleteHandler: %p %s
StatusHandler: %p %s
StatusHandler: %p %s
StatusCompleteHandler: %p %s
StatusCompleteHandler: %p %s
ReceivePacketHandler: %p %s
ReceivePacketHandler: %p %s
BindAdapterHandler: %p %s
BindAdapterHandler: %p %s
UnbindAdapterHandler: %p %s
UnbindAdapterHandler: %p %s
PnPEventHandler: %p %s
PnPEventHandler: %p %s
UnloadHandler: %p %s
UnloadHandler: %p %s
CoSendCompleteHandler: %p %s
CoSendCompleteHandler: %p %s
CoStatusHandler: %p %s
CoStatusHandler: %p %s
CoReceivePacketHandler: %p %s
CoReceivePacketHandler: %p %s
CoAfRegisterNotifyHandler: %p %s
CoAfRegisterNotifyHandler: %p %s
MajorNdisVersion %d
MajorNdisVersion %d
MinorNdisVersion %d
MinorNdisVersion %d
MajorDriverVersion %d
MajorDriverVersion %d
MinorDriverVersion %d
MinorDriverVersion %d
Flags %X
Flags %X
IsIPv4 %d
IsIPv4 %d
IsIPv6 %d
IsIPv6 %d
IsNdisTest6 %d
IsNdisTest6 %d
BindAdapterHandlerEx: %p %s
BindAdapterHandlerEx: %p %s
UnbindAdapterHandlerEx: %p %s
UnbindAdapterHandlerEx: %p %s
OpenAdapterCompleteHandlerEx: %p %s
OpenAdapterCompleteHandlerEx: %p %s
CloseAdapterCompleteHandlerEx: %p %s
CloseAdapterCompleteHandlerEx: %p %s
PnPEventHandler: %p %s
PnPEventHandler: %p %s
UnloadHandler: %p %s
UnloadHandler: %p %s
UninstallHandler: %p %s
UninstallHandler: %p %s
RequestCompleteHandler: %p %s
RequestCompleteHandler: %p %s
StatusHandler: %p %s
StatusHandler: %p %s
StatusCompleteHandler: %p %s
StatusCompleteHandler: %p %s
ReceiveNetBufferListsHandler: %p %s
ReceiveNetBufferListsHandler: %p %s
SendNetBufferListsCompleteHandler: %p %s
SendNetBufferListsCompleteHandler: %p %s
CoStatusHandler: %p %s
CoStatusHandler: %p %s
CoAfRegisterNotifyHandler: %p %s
CoAfRegisterNotifyHandler: %p %s
CoReceiveNetBufferListsHandler: %p %s
CoReceiveNetBufferListsHandler: %p %s
CoSendNetBufferListsCompleteHandler: %p %s
CoSendNetBufferListsCompleteHandler: %p %s
OpenAdapterCompleteHandler: %p %s
OpenAdapterCompleteHandler: %p %s
CloseAdapterCompleteHandler: %p %s
CloseAdapterCompleteHandler: %p %s
SendCompleteHandler: %p %s
SendCompleteHandler: %p %s
TransferDataCompleteHandler: %p %s
TransferDataCompleteHandler: %p %s
ResetCompleteHandler: %p %s
ResetCompleteHandler: %p %s
ReceiveHandler: %p %s
ReceiveHandler: %p %s
ReceiveCompleteHandler: %p %s
ReceiveCompleteHandler: %p %s
ReceivePacketHandler: %p %s
ReceivePacketHandler: %p %s
BindAdapterHandler: %p %s
BindAdapterHandler: %p %s
UnbindAdapterHandler: %p %s
UnbindAdapterHandler: %p %s
CoSendCompleteHandler: %p %s
CoSendCompleteHandler: %p %s
CoReceivePacketHandler: %p %s
CoReceivePacketHandler: %p %s
OidRequestCompleteHandler: %p %s
OidRequestCompleteHandler: %p %s
InitiateOffloadCompleteHandler: %p %s
InitiateOffloadCompleteHandler: %p %s
TerminateOffloadCompleteHandler: %p %s
TerminateOffloadCompleteHandler: %p %s
UpdateOffloadCompleteHandler: %p %s
UpdateOffloadCompleteHandler: %p %s
InvalidateOffloadCompleteHandler: %p %s
InvalidateOffloadCompleteHandler: %p %s
QueryOffloadCompleteHandler: %p %s
QueryOffloadCompleteHandler: %p %s
IndicateOffloadEventHandler: %p %s
IndicateOffloadEventHandler: %p %s
TcpOffloadSendCompleteHandler: %p %s
TcpOffloadSendCompleteHandler: %p %s
TcpOffloadReceiveCompleteHandler: %p %s
TcpOffloadReceiveCompleteHandler: %p %s
TcpOffloadDisconnectCompleteHandler: %p %s
TcpOffloadDisconnectCompleteHandler: %p %s
TcpOffloadForwardCompleteHandler: %p %s
TcpOffloadForwardCompleteHandler: %p %s
TcpOffloadEventHandler: %p %s
TcpOffloadEventHandler: %p %s
TcpOffloadReceiveIndicateHandler: %p %s
TcpOffloadReceiveIndicateHandler: %p %s
Unknown NDIS Type %X and Size %X
Unknown NDIS Type %X and Size %X
DirectOidRequestCompleteHandler: %p %s
DirectOidRequestCompleteHandler: %p %s
AllocateSharedMemoryHandler: %p %s
AllocateSharedMemoryHandler: %p %s
FreeSharedMemoryHandler: %p %s
FreeSharedMemoryHandler: %p %s
Unknown ndis protocol size: %X
Unknown ndis protocol size: %X
NDIS MiniDriver[%d] %p
NDIS MiniDriver[%d] %p
MajorNdisVersion: %d
MajorNdisVersion: %d
MinorNdisVersion: %d
MinorNdisVersion: %d
CheckForHangHandler: %p %s
CheckForHangHandler: %p %s
DisableInterruptHandler: %p %s
DisableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
HaltHandler %p %s
HaltHandler %p %s
HandleInterruptHandler: %p %s
HandleInterruptHandler: %p %s
InitializeHandler: %p %s
InitializeHandler: %p %s
ISRHandler: %p %s
ISRHandler: %p %s
QueryInformationHandler: %p %s
QueryInformationHandler: %p %s
ReconfigureHandler: %p %s
ReconfigureHandler: %p %s
ResetHandler: %p %s
ResetHandler: %p %s
SendHandler: %p %s
SendHandler: %p %s
SetInformationHandler: %p %s
SetInformationHandler: %p %s
TransferDataHandler: %p %s
TransferDataHandler: %p %s
ReturnPacketHandler: %p %s
ReturnPacketHandler: %p %s
SendPacketsHandler: %p %s
SendPacketsHandler: %p %s
AllocateCompleteHandler: %p %s
AllocateCompleteHandler: %p %s
CoCreateVcHandler: %p %s
CoCreateVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoActivateVcHandler: %p %s
CoActivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoSendPacketsHandler: %p %s
CoSendPacketsHandler: %p %s
CoRequestHandler: %p %s
CoRequestHandler: %p %s
CheckForHangHandler: %p %s
CheckForHangHandler: %p %s
DisableInterruptHandler: %p %s
DisableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
HaltHandler %p %s
HaltHandler %p %s
HandleInterruptHandler: %p %s
HandleInterruptHandler: %p %s
InitializeHandler: %p %s
InitializeHandler: %p %s
ISRHandler: %p %s
ISRHandler: %p %s
QueryInformationHandler: %p %s
QueryInformationHandler: %p %s
ReconfigureHandler: %p %s
ReconfigureHandler: %p %s
ResetHandler: %p %s
ResetHandler: %p %s
SendHandler: %p %s
SendHandler: %p %s
SetInformationHandler: %p %s
SetInformationHandler: %p %s
TransferDataHandler: %p %s
TransferDataHandler: %p %s
ReturnPacketHandler: %p %s
ReturnPacketHandler: %p %s
SendPacketsHandler: %p %s
SendPacketsHandler: %p %s
AllocateCompleteHandler: %p %s
AllocateCompleteHandler: %p %s
CoCreateVcHandler: %p %s
CoCreateVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoActivateVcHandler: %p %s
CoActivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoSendPacketsHandler: %p %s
CoSendPacketsHandler: %p %s
CoRequestHandler: %p %s
CoRequestHandler: %p %s
CancelSendPacketsHandler: %p %s
CancelSendPacketsHandler: %p %s
PnPEventNotifyHandler: %p %s
PnPEventNotifyHandler: %p %s
AdapterShutdownHandler: %p %s
AdapterShutdownHandler: %p %s
CheckForHangHandler: %p %s
CheckForHangHandler: %p %s
DisableInterruptHandler: %p %s
DisableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
HaltHandler %p %s
HaltHandler %p %s
HandleInterruptHandler: %p %s
HandleInterruptHandler: %p %s
InitializeHandler: %p %s
InitializeHandler: %p %s
ISRHandler: %p %s
ISRHandler: %p %s
QueryInformationHandler: %p %s
QueryInformationHandler: %p %s
ReconfigureHandler: %p %s
ReconfigureHandler: %p %s
ResetHandler: %p %s
ResetHandler: %p %s
SendHandler: %p %s
SendHandler: %p %s
SetInformationHandler: %p %s
SetInformationHandler: %p %s
TransferDataHandler: %p %s
TransferDataHandler: %p %s
ReturnPacketHandler: %p %s
ReturnPacketHandler: %p %s
SendPacketsHandler: %p %s
SendPacketsHandler: %p %s
AllocateCompleteHandler: %p %s
AllocateCompleteHandler: %p %s
CoCreateVcHandler: %p %s
CoCreateVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoActivateVcHandler: %p %s
CoActivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoSendPacketsHandler: %p %s
CoSendPacketsHandler: %p %s
CoRequestHandler: %p %s
CoRequestHandler: %p %s
CancelSendPacketsHandler: %p %s
CancelSendPacketsHandler: %p %s
PnPEventNotifyHandler: %p %s
PnPEventNotifyHandler: %p %s
AdapterShutdownHandler: %p %s
AdapterShutdownHandler: %p %s
ISRHandlerEx: %p %s
ISRHandlerEx: %p %s
HandleInterruptHandlerEx: %p %s
HandleInterruptHandlerEx: %p %s
InitiateOffloadHandler: %p %s
InitiateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
QueryOffloadHandler: %p %s
QueryOffloadHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
ReturnPacketsHandlerEx: %p %s
ReturnPacketsHandlerEx: %p %s
RequestTimeoutDpcHandler: %p %s
RequestTimeoutDpcHandler: %p %s
MajorNdisVersion: %d
MajorNdisVersion: %d
MinorNdisVersion: %d
MinorNdisVersion: %d
MajorDriverVersion: %d
MajorDriverVersion: %d
MinorDriverVersion: %d
MinorDriverVersion: %d
Flags: %X
Flags: %X
SetOptionsHandler: %p %s
SetOptionsHandler: %p %s
InitializeHandlerEx: %p %s
InitializeHandlerEx: %p %s
HaltHandlerEx: %p %s
HaltHandlerEx: %p %s
UnloadHandler: %p %s
UnloadHandler: %p %s
PauseHandler: %p %s
PauseHandler: %p %s
RestartHandler: %p %s
RestartHandler: %p %s
OidRequestHandler: %p %s
OidRequestHandler: %p %s
SendNetBufferListsHandler: %p %s
SendNetBufferListsHandler: %p %s
ReturnNetBufferListsHandler: %p %s
ReturnNetBufferListsHandler: %p %s
CancelSendHandler: %p %s
CancelSendHandler: %p %s
CheckForHangHandlerEx: %p %s
CheckForHangHandlerEx: %p %s
ResetHandlerEx: %p %s
ResetHandlerEx: %p %s
DevicePnPEventNotifyHandler: %p %s
DevicePnPEventNotifyHandler: %p %s
ShutdownHandlerEx: %p %s
ShutdownHandlerEx: %p %s
CancelOidRequestHandler: %p %s
CancelOidRequestHandler: %p %s
DirectOidRequestHandler: %p %s
DirectOidRequestHandler: %p %s
CancelDirectOidRequestHandler: %p %s
CancelDirectOidRequestHandler: %p %s
NDIS MiniPort[%d] %p
NDIS MiniPort[%d] %p
State: %s
State: %s
MediaType: %s
MediaType: %s
AdapterType: %s
AdapterType: %s
DefaultSendAuthorizationState: %s
DefaultSendAuthorizationState: %s
DefaultRcvAuthorizationState: %s
DefaultRcvAuthorizationState: %s
DefaultPortSendAuthorizationState: %s
DefaultPortSendAuthorizationState: %s
DefaultPortRcvAuthorizationState: %s
DefaultPortRcvAuthorizationState: %s
NextCancelSendNetBufferListsHandler: %p %s
NextCancelSendNetBufferListsHandler: %p %s
PacketIndicateHandler: %p %s
PacketIndicateHandler: %p %s
SendCompleteHandler: %p %s
SendCompleteHandler: %p %s
SendResourcesHandler: %p %s
SendResourcesHandler: %p %s
ResetCompleteHandler: %p %s
ResetCompleteHandler: %p %s
DisableInterruptHandler: %p %s
DisableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
EnableInterruptHandler: %p %s
SendPacketsHandler: %p %s
SendPacketsHandler: %p %s
DeferredSendHandler: %p %s
DeferredSendHandler: %p %s
EthRxIndicateHandler: %p %s
EthRxIndicateHandler: %p %s
NextSendNetBufferListsHandler: %p %s
NextSendNetBufferListsHandler: %p %s
EthRxCompleteHandler: %p %s
EthRxCompleteHandler: %p %s
SavedNextSendNetBufferListsHandler: %p %s
SavedNextSendNetBufferListsHandler: %p %s
StatusHandler: %p %s
StatusHandler: %p %s
StatusCompleteHandler: %p %s
StatusCompleteHandler: %p %s
TDCompleteHandler: %p %s
TDCompleteHandler: %p %s
QueryCompleteHandler: %p %s
QueryCompleteHandler: %p %s
SetCompleteHandler: %p %s
SetCompleteHandler: %p %s
WanSendCompleteHandler: %p %s
WanSendCompleteHandler: %p %s
WanRcvHandler: %p %s
WanRcvHandler: %p %s
WanRcvCompleteHandler: %p %s
WanRcvCompleteHandler: %p %s
SendNetBufferListsCompleteHandler: %p %s
SendNetBufferListsCompleteHandler: %p %s
WSendPacketsHandler: %p %s
WSendPacketsHandler: %p %s
NextSendPacketsHandler: %p %s
NextSendPacketsHandler: %p %s
FinalSendPacketsHandler: %p %s
FinalSendPacketsHandler: %p %s
TopIndicateNetBufferListsHandler: %p %s
TopIndicateNetBufferListsHandler: %p %s
TopIndicateLoopbackNetBufferListsHandler: %p %s
TopIndicateLoopbackNetBufferListsHandler: %p %s
Ndis5PacketIndicateHandler: %p %s
Ndis5PacketIndicateHandler: %p %s
MiniportReturnPacketHandler: %p %s
MiniportReturnPacketHandler: %p %s
SynchronousReturnPacketHandler: %p %s
SynchronousReturnPacketHandler: %p %s
TopNdis5PacketIndicateHandler: %p %s
TopNdis5PacketIndicateHandler: %p %s
AllocateSharedMemoryHandler: %p %s
AllocateSharedMemoryHandler: %p %s
FreeSharedMemoryHandler: %p %s
FreeSharedMemoryHandler: %p %s
SetBusData: %p %s
SetBusData: %p %s
GetBusData: %p %s
GetBusData: %p %s
NoFilter.CancelSendHandler %p %s
NoFilter.CancelSendHandler %p %s
NoFilter.SendNetBufferListsCompleteHandler %p %s
NoFilter.SendNetBufferListsCompleteHandler %p %s
NoFilter.IndicateNetBufferListsHandler %p %s
NoFilter.IndicateNetBufferListsHandler %p %s
NoFilter.SaveIndicateNetBufferListsHandler %p %s
NoFilter.SaveIndicateNetBufferListsHandler %p %s
NoFilter.ReturnNetBufferListsHandler %p %s
NoFilter.ReturnNetBufferListsHandler %p %s
NoFilter.SendNetBufferListsHandler %p %s
NoFilter.SendNetBufferListsHandler %p %s
Next.CancelSendHandler %p %s
Next.CancelSendHandler %p %s
Next.SendNetBufferListsCompleteHandler %p %s
Next.SendNetBufferListsCompleteHandler %p %s
Next.IndicateNetBufferListsHandler %p %s
Next.IndicateNetBufferListsHandler %p %s
Next.SaveIndicateNetBufferListsHandler %p %s
Next.SaveIndicateNetBufferListsHandler %p %s
Next.ReturnNetBufferListsHandler %p %s
Next.ReturnNetBufferListsHandler %p %s
Next.SendNetBufferListsHandler %p %s
Next.SendNetBufferListsHandler %p %s
Name: %S
Name: %S
BaseName: %S
BaseName: %S
SymbolicLinkName: %S
SymbolicLinkName: %S
NextCancelSendNetBufferListsHandler %p %s
NextCancelSendNetBufferListsHandler %p %s
TrRxIndicateHandler: %p %s
TrRxIndicateHandler: %p %s
TrRxCompleteHandler: %p %s
TrRxCompleteHandler: %p %s
IndicateNetBufferListsHandler: %p %s
IndicateNetBufferListsHandler: %p %s
NextReturnNetBufferLists: %p %s
NextReturnNetBufferLists: %p %s
SavedIndicateNetBufferListsHandler: %p %s
SavedIndicateNetBufferListsHandler: %p %s
SavedPacketIndicateHandler: %p %s
SavedPacketIndicateHandler: %p %s
ShutdownHandler: %p %s
ShutdownHandler: %p %s
NDIS MiniPort[%d] %S
NDIS MiniPort[%d] %S
BusType: %s
BusType: %s
PacketIndicateHandler: %p %s
PacketIndicateHandler: %p %s
SendCompleteHandler: %p %s
SendCompleteHandler: %p %s
SendResourcesHandler: %p %s
SendResourcesHandler: %p %s
ResetCompleteHandler: %p %s
ResetCompleteHandler: %p %s
DeferredSendHandler: %p %s
DeferredSendHandler: %p %s
EthRxIndicateHandler: %p %s
EthRxIndicateHandler: %p %s
TrRxIndicateHandler: %p %s
TrRxIndicateHandler: %p %s
FddiRxIndicateHandler: %p %s
FddiRxIndicateHandler: %p %s
EthRxCompleteHandler: %p %s
EthRxCompleteHandler: %p %s
TrRxCompleteHandler: %p %s
TrRxCompleteHandler: %p %s
FddiRxCompleteHandler: %p %s
FddiRxCompleteHandler: %p %s
StatusHandler: %p %s
StatusHandler: %p %s
StatusCompleteHandler: %p %s
StatusCompleteHandler: %p %s
TDCompleteHandler: %p %s
TDCompleteHandler: %p %s
QueryCompleteHandler: %p %s
QueryCompleteHandler: %p %s
SetCompleteHandler: %p %s
SetCompleteHandler: %p %s
WanSendCompleteHandler: %p %s
WanSendCompleteHandler: %p %s
WanRcvHandler: %p %s
WanRcvHandler: %p %s
WanRcvCompleteHandler: %p %s
WanRcvCompleteHandler: %p %s
AdapterInstanceName: %S
AdapterInstanceName: %S
OpenBlock [%d] %p
OpenBlock [%d] %p
RootName: %S
RootName: %S
BindName: %S
BindName: %S
ProtocolMajorVersion: %X
ProtocolMajorVersion: %X
NextSendHandler: %p %s
NextSendHandler: %p %s
NextReturnNetBufferListsHandler: %p %s
NextReturnNetBufferListsHandler: %p %s
SendHandler: %p %s
SendHandler: %p %s
TransferDataHandler: %p %s
TransferDataHandler: %p %s
WanReceiveHandler: %p %s
WanReceiveHandler: %p %s
SendPacketsHandler: %p %s
SendPacketsHandler: %p %s
ResetHandler: %p %s
ResetHandler: %p %s
RequestHandler: %p %s
RequestHandler: %p %s
OidRequestHandler: %p %s
OidRequestHandler: %p %s
WSendHandler: %p %s
WSendHandler: %p %s
WTransferDataHandler: %p %s
WTransferDataHandler: %p %s
WSendPacketsHandler: %p %s
WSendPacketsHandler: %p %s
CancelSendPacketsHandler: %p %s
CancelSendPacketsHandler: %p %s
ProtSendNetBufferListsComplete: %p %s
ProtSendNetBufferListsComplete: %p %s
NextSendNetBufferListsComplete: %p %s
NextSendNetBufferListsComplete: %p %s
ReceiveNetBufferLists: %p %s
ReceiveNetBufferLists: %p %s
SavedSendNBLHandler: %p %s
SavedSendNBLHandler: %p %s
SavedSendPacketsHandler: %p %s
SavedSendPacketsHandler: %p %s
SavedCancelSendPacketsHandler: %p %s
SavedCancelSendPacketsHandler: %p %s
SavedSendHandler: %p %s
SavedSendHandler: %p %s
Ndis5WanSendHandler: %p %s
Ndis5WanSendHandler: %p %s
ProtSendCompleteHandler: %p %s
ProtSendCompleteHandler: %p %s
OidRequestCompleteHandler %p %s
OidRequestCompleteHandler %p %s
OpenFlags: %X
OpenFlags: %X
DirectOidRequestHandler: %p %s
DirectOidRequestHandler: %p %s
RootName: %S
RootName: %S
BindName: %S
BindName: %S
Flags: %X
Flags: %X
SendHandler: %p %s
SendHandler: %p %s
WanSendHandler: %p %s
WanSendHandler: %p %s
TransferDataHandler: %p %s
TransferDataHandler: %p %s
WanReceiveHandler: %p %s
WanReceiveHandler: %p %s
SendPacketsHandler: %p %s
SendPacketsHandler: %p %s
ResetHandler: %p %s
ResetHandler: %p %s
RequestHandler: %p %s
RequestHandler: %p %s
WSendHandler: %p %s
WSendHandler: %p %s
WTransferDataHandler: %p %s
WTransferDataHandler: %p %s
WSendPacketsHandler: %p %s
WSendPacketsHandler: %p %s
CancelSendPacketsHandler: %p %s
CancelSendPacketsHandler: %p %s
Flags %X
Flags %X
Mtu %X
Mtu %X
PromiscuousMode %d
PromiscuousMode %d
AccessType %s
AccessType %s
DirectionType %s
DirectionType %s
ConnectionType %s
ConnectionType %s
MediaType %s
MediaType %s
MediaConnectState %s
MediaConnectState %s
AdminStatus %s
AdminStatus %s
OperStatus %s
OperStatus %s
InterfaceGuid %s
InterfaceGuid %s
NetworkGuid %s
NetworkGuid %s
ifIndex %X
ifIndex %X
ifDescr %S
ifDescr %S
ifAlias %S
ifAlias %S
FilterDriverCharacteristics[%d]:
FilterDriverCharacteristics[%d]:
FriendlyName: %S
FriendlyName: %S
UniqueName: %S
UniqueName: %S
ServiceName: %S
ServiceName: %S
SetOptionsHandler: %p %s
SetOptionsHandler: %p %s
SetFilterModuleOptionsHandler: %p %s
SetFilterModuleOptionsHandler: %p %s
AttachHandler: %p %s
AttachHandler: %p %s
DetachHandler: %p %s
DetachHandler: %p %s
RestartHandler: %p %s
RestartHandler: %p %s
PauseHandler: %p %s
PauseHandler: %p %s
SendNetBufferListsHandler: %p %s
SendNetBufferListsHandler: %p %s
SendNetBufferListsCompleteHandler: %p %s
SendNetBufferListsCompleteHandler: %p %s
CancelSendNetBufferListsHandler: %p %s
CancelSendNetBufferListsHandler: %p %s
ReceiveNetBufferListsHandler: %p %s
ReceiveNetBufferListsHandler: %p %s
ReturnNetBufferListsHandler: %p %s
ReturnNetBufferListsHandler: %p %s
OidRequestHandler: %p %s
OidRequestHandler: %p %s
OidRequestCompleteHandler: %p %s
OidRequestCompleteHandler: %p %s
CancelOidRequestHandler: %p %s
CancelOidRequestHandler: %p %s
DevicePnPEventNotifyHandler: %p %s
DevicePnPEventNotifyHandler: %p %s
NetPnPEventHandler: %p %s
NetPnPEventHandler: %p %s
StatusHandler: %p %s
StatusHandler: %p %s
DirectOidRequestHandler: %p %s
DirectOidRequestHandler: %p %s
DirectOidRequestCompleteHandler: %p %s
DirectOidRequestCompleteHandler: %p %s
CancelDirectOidRequestHandler: %p %s
CancelDirectOidRequestHandler: %p %s
InterfaceGuid: %s
InterfaceGuid: %s
FilterState: %s
FilterState: %s
NextSendNetBufferListsHandler: %p %s
NextSendNetBufferListsHandler: %p %s
NextSendNetBufferListsCompleteHandler: %p %s
NextSendNetBufferListsCompleteHandler: %p %s
NextIndicateReceiveNetBufferListsHandler: %p %s
NextIndicateReceiveNetBufferListsHandler: %p %s
NextReturnNetBufferListsHandler: %p %s
NextReturnNetBufferListsHandler: %p %s
NextCancelSendNetBufferListsHandler: %p %s
NextCancelSendNetBufferListsHandler: %p %s
SetFilterModuleOptionalHandlers: %p %s
SetFilterModuleOptionalHandlers: %p %s
OidRequestHandler: %p %s
OidRequestHandler: %p %s
OidRequestCompleteHandler: %p %s
OidRequestCompleteHandler: %p %s
CancelRequestHandler: %p %s
CancelRequestHandler: %p %s
DevicePnPEventNotifyHandler: %p %s
DevicePnPEventNotifyHandler: %p %s
NetPnPEventHandler: %p %s
NetPnPEventHandler: %p %s
StatusHandler: %p %s
StatusHandler: %p %s
FilterSendNetBufferListsHandler: %p %s
FilterSendNetBufferListsHandler: %p %s
FilterIndicateReceiveNetBufferListsHandler: %p %s
FilterIndicateReceiveNetBufferListsHandler: %p %s
FilterCancelSendNetBufferListsHandler: %p %s
FilterCancelSendNetBufferListsHandler: %p %s
InitiateOffloadCompleteHandler: %p %s
InitiateOffloadCompleteHandler: %p %s
TerminateOffloadCompleteHandler: %p %s
TerminateOffloadCompleteHandler: %p %s
UpdateOffloadCompleteHandler: %p %s
UpdateOffloadCompleteHandler: %p %s
InvalidateOffloadCompleteHandler: %p %s
InvalidateOffloadCompleteHandler: %p %s
QueryOffloadCompleteHandler: %p %s
QueryOffloadCompleteHandler: %p %s
IndicateOffloadEventHandler: %p %s
IndicateOffloadEventHandler: %p %s
TcpOffloadSendCompleteHandler: %p %s
TcpOffloadSendCompleteHandler: %p %s
TcpOffloadReceiveCompleteHandler: %p %s
TcpOffloadReceiveCompleteHandler: %p %s
TcpOffloadDisconnectCompleteHandler: %p %s
TcpOffloadDisconnectCompleteHandler: %p %s
TcpOffloadForwardCompleteHandler: %p %s
TcpOffloadForwardCompleteHandler: %p %s
TcpOffloadEventHandler: %p %s
TcpOffloadEventHandler: %p %s
TcpOffloadReceiveIndicateHandler: %p %s
TcpOffloadReceiveIndicateHandler: %p %s
InitiateOffloadHandler: %p %s
InitiateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
QueryOffloadHandler: %p %s
QueryOffloadHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
DirectOidRequestHandler: %p %s
DirectOidRequestHandler: %p %s
DirectOidRequestCompleteHandler: %p %s
DirectOidRequestCompleteHandler: %p %s
CancelDirectOidRequestHandler: %p %s
CancelDirectOidRequestHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadForwardHandler: %p %s
Provider[%d]: %p
Provider[%d]: %p
QueryObjectHandler: %p %s
QueryObjectHandler: %p %s
SetObjectHandler: %p %s
SetObjectHandler: %p %s
FilterDriverBlock[%d]
FilterDriverBlock[%d]
InitiateOffloadHandler: %p %s
InitiateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
QueryOffloadHandler: %p %s
QueryOffloadHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadForwardHandler: %p %s
ClCreateVcHandler: %p %s
ClCreateVcHandler: %p %s
ClDeleteVcHandler: %p %s
ClDeleteVcHandler: %p %s
ClOidRequestHandler: %p %s
ClOidRequestHandler: %p %s
ClOidRequestCompleteHandler: %p %s
ClOidRequestCompleteHandler: %p %s
ClOpenAfCompleteHandlerEx: %p %s
ClOpenAfCompleteHandlerEx: %p %s
ClCloseAfCompleteHandler: %p %s
ClCloseAfCompleteHandler: %p %s
ClRegisterSapCompleteHandler: %p %s
ClRegisterSapCompleteHandler: %p %s
ClDeregisterSapCompleteHandler: %p %s
ClDeregisterSapCompleteHandler: %p %s
ClMakeCallCompleteHandler: %p %s
ClMakeCallCompleteHandler: %p %s
ClModifyCallQoSCompleteHandler: %p %s
ClModifyCallQoSCompleteHandler: %p %s
ClCloseCallCompleteHandler: %p %s
ClCloseCallCompleteHandler: %p %s
ClAddPartyCompleteHandler: %p %s
ClAddPartyCompleteHandler: %p %s
ClDropPartyCompleteHandler: %p %s
ClDropPartyCompleteHandler: %p %s
ClIncomingCallHandler: %p %s
ClIncomingCallHandler: %p %s
ClIncomingCallQoSChangeHandler: %p %s
ClIncomingCallQoSChangeHandler: %p %s
ClIncomingCloseCallHandler: %p %s
ClIncomingCloseCallHandler: %p %s
ClIncomingDropPartyHandler: %p %s
ClIncomingDropPartyHandler: %p %s
ClCallConnectedHandler: %p %s
ClCallConnectedHandler: %p %s
ClNotifyCloseAfHandler: %p %s
ClNotifyCloseAfHandler: %p %s
CmCreateVcHandler: %p %s
CmCreateVcHandler: %p %s
CmDeleteVcHandler: %p %s
CmDeleteVcHandler: %p %s
CmOpenAfHandler: %p %s
CmOpenAfHandler: %p %s
CmCloseAfHandler: %p %s
CmCloseAfHandler: %p %s
CmRegisterSapHandler: %p %s
CmRegisterSapHandler: %p %s
CmDeregisterSapHandler: %p %s
CmDeregisterSapHandler: %p %s
CmMakeCallHandler: %p %s
CmMakeCallHandler: %p %s
CmCloseCallHandler: %p %s
CmCloseCallHandler: %p %s
CmIncomingCallCompleteHandler: %p %s
CmIncomingCallCompleteHandler: %p %s
CmAddPartyHandler: %p %s
CmAddPartyHandler: %p %s
CmDropPartyHandler: %p %s
CmDropPartyHandler: %p %s
CmActivateVcCompleteHandler: %p %s
CmActivateVcCompleteHandler: %p %s
CmDeactivateVcCompleteHandler: %p %s
CmDeactivateVcCompleteHandler: %p %s
CmModifyCallQoSHandler: %p %s
CmModifyCallQoSHandler: %p %s
CmOidRequestHandler: %p %s
CmOidRequestHandler: %p %s
CmOidRequestCompleteHandler: %p %s
CmOidRequestCompleteHandler: %p %s
CmNotifyCloseAfCompleteHandler: %p %s
CmNotifyCloseAfCompleteHandler: %p %s
DriverVersion: %X
DriverVersion: %X
CoCreateVcHandler: %p %s
CoCreateVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoActivateVcHandler: %p %s
CoActivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoSendNetBufferListsHandler: %p %s
CoSendNetBufferListsHandler: %p %s
CoRequestHandler: %p %s
CoRequestHandler: %p %s
CoOidRequestHandler: %p %s
CoOidRequestHandler: %p %s
InitiateOffloadHandler: %p %s
InitiateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
QueryOffloadHandler: %p %s
QueryOffloadHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
AddDeviceHandler: %p %s
AddDeviceHandler: %p %s
RemoveDeviceHandler: %p %s
RemoveDeviceHandler: %p %s
FilterResourceRequirementsHandler: %p %s
FilterResourceRequirementsHandler: %p %s
StartDeviceHandler: %p %s
StartDeviceHandler: %p %s
ServiceName: %S
ServiceName: %S
CoCreateVcHandler: %p %s
CoCreateVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoDeleteVcHandler: %p %s
CoActivateVcHandler: %p %s
CoActivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoDeactivateVcHandler: %p %s
CoSendNetBufferListsHandler: %p %s
CoSendNetBufferListsHandler: %p %s
CoRequestHandler: %p %s
CoRequestHandler: %p %s
CoOidRequestHandler: %p %s
CoOidRequestHandler: %p %s
InitiateOffloadHandler: %p %s
InitiateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
TerminateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
UpdateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
InvalidateOffloadHandler: %p %s
QueryOffloadHandler: %p %s
QueryOffloadHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadSendHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadReceiveHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadDisconnectHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadForwardHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
TcpOffloadReceiveReturnHandler: %p %s
AddDeviceHandler: %p %s
AddDeviceHandler: %p %s
RemoveDeviceHandler: %p %s
RemoveDeviceHandler: %p %s
FilterResourceRequirementsHandler: %p %s
FilterResourceRequirementsHandler: %p %s
StartDeviceHandler: %p %s
StartDeviceHandler: %p %s
OpenNDKAdapterHandler: %p %s
OpenNDKAdapterHandler: %p %s
CloseNDKAdapterHandler: %p %s
CloseNDKAdapterHandler: %p %s
IdleNotificationHandler: %p %s
IdleNotificationHandler: %p %s
CancelIdleNotificationHandler: %p %s
CancelIdleNotificationHandler: %p %s
AllocateNetBufferListForwardingContextHandler: %p %s
AllocateNetBufferListForwardingContextHandler: %p %s
FreeNetBufferListForwardingContextHandler: %p %s
FreeNetBufferListForwardingContextHandler: %p %s
AddNetBufferListDestinationHandler: %p %s
AddNetBufferListDestinationHandler: %p %s
SetNetBufferListSourceHandler: %p %s
SetNetBufferListSourceHandler: %p %s
GrowNetBufferListDestinationsHandler: %p %s
GrowNetBufferListDestinationsHandler: %p %s
GetNetBufferListDestinationsHandler: %p %s
GetNetBufferListDestinationsHandler: %p %s
UpdateNetBufferListDestinationsHandler: %p %s
UpdateNetBufferListDestinationsHandler: %p %s
CopyNetBufferListInfoHandler: %p %s
CopyNetBufferListInfoHandler: %p %s
ReferenceSwitchNicHandler: %p %s
ReferenceSwitchNicHandler: %p %s
DereferenceSwitchNicHandler: %p %s
DereferenceSwitchNicHandler: %p %s
ReferenceSwitchPortHandler: %p %s
ReferenceSwitchPortHandler: %p %s
DereferenceSwitchPortHandler: %p %s
DereferenceSwitchPortHandler: %p %s
ReportFilteredNetBufferListsHandler: %p %s
ReportFilteredNetBufferListsHandler: %p %s
ImageName: %S
ImageName: %S
SetNetBufferListSwitchContextHandler: %p %s
SetNetBufferListSwitchContextHandler: %p %s
GetNetBufferListSwitchContextHandler: %p %s
GetNetBufferListSwitchContextHandler: %p %s
netio legacy handler %p %s
netio legacy handler %p %s
read netio legacy handler failed, error %d, status %X
read netio legacy handler failed, error %d, status %X
read netio legacy handler failed, error %d
read netio legacy handler failed, error %d
%p %s
%p %s
read netio WfpNblInfoDispTable failed, error %d, status %X
read netio WfpNblInfoDispTable failed, error %d, status %X
read netio WfpNblInfoDispTable failed, error %d
read netio WfpNblInfoDispTable failed, error %d
netio MacShim %p %s
netio MacShim %p %s
WfpShim[%d] %p %s
WfpShim[%d] %p %s
Unknown WFP callout size %d
Unknown WFP callout size %d
WFP callout[%d]:
WFP callout[%d]:
ClassifyCallback: %p %s
ClassifyCallback: %p %s
NotifyCallback: %p %s
NotifyCallback: %p %s
uFlowDeleteFunction: %p %s
uFlowDeleteFunction: %p %s
Exception %X on sysptr seed reading at %p
Exception %X on sysptr seed reading at %p
Decode system scheme - %s
Decode system scheme - %s
Decode scheme - %s
Decode scheme - %s
Cannot read my process cookie, error %X
Cannot read my process cookie, error %X
Trace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X (%p) %s
Trace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X (%p) %s
Trace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X %p
Trace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X %p
SystemFunction%3.3d (%p) %s
SystemFunction%3.3d (%p) %s
PFNCLIENT.%s patched by %s (%p)
PFNCLIENT.%s patched by %s (%p)
PFNCLIENT.%s patched %p
PFNCLIENT.%s patched %p
check_user32_pfnclient: exception %X occured
check_user32_pfnclient: exception %X occured
PFNCLIENTWORKER.%s patched by %s (%p)
PFNCLIENTWORKER.%s patched by %s (%p)
PFNCLIENTWORKER.%s patched %p
PFNCLIENTWORKER.%s patched %p
ConsoleCtrlHandler[%d]: %s (%p)
ConsoleCtrlHandler[%d]: %s (%p)
ConsoleCtrlHandler[%d]: %p UNKNOWN
ConsoleCtrlHandler[%d]: %p UNKNOWN
ConsoleCtrlHandler: %s (%p)
ConsoleCtrlHandler: %s (%p)
UnhandledExceptionFilter: %s (%p)
UnhandledExceptionFilter: %s (%p)
ShimModule: %s (%p)
ShimModule: %s (%p)
RtlpStartThreadFunc: %s (%p)
RtlpStartThreadFunc: %s (%p)
RtlpExitThreadFunc: %s (%p)
RtlpExitThreadFunc: %s (%p)
RtlpUnhandledExceptionFilter: %s (%p)
RtlpUnhandledExceptionFilter: %s (%p)
RtlSecureMemoryCacheCallback: %s (%p)
RtlSecureMemoryCacheCallback: %s (%p)
TppLogpRoutine: %s (%p)
TppLogpRoutine: %s (%p)
CsrServerApiRoutine: %s (%p)
CsrServerApiRoutine: %s (%p)
LdrpManifestProberRoutine: %s (%p)
LdrpManifestProberRoutine: %s (%p)
LdrpCreateActCtxLanguage: %s (%p)
LdrpCreateActCtxLanguage: %s (%p)
LdrpReleaseActCtx: %s (%p)
LdrpReleaseActCtx: %s (%p)
LdrpAppCompatDllRedirectionCallbackFunction: %s (%p)
LdrpAppCompatDllRedirectionCallbackFunction: %s (%p)
%s%s!%s patched by %s (addr %p)
%s%s!%s patched by %s (addr %p)
%s%s.%d patched by %s (addr %p)
%s%s.%d patched by %s (addr %p)
%s%s.%d patched, addr %p
%s%s.%d patched, addr %p
PID %d trace callbacks: %d
PID %d trace callbacks: %d
Trace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X %p %s
Trace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X %p %s
Process PID %d has the same token as system process: %p !!!
Process PID %d has the same token as system process: %p !!!
Process PID %d token: %p
Process PID %d token: %p
%p %s %8X
%p %s %8X
%p %s %8X
%p %s %8X
CheckProc: cannot get modules list for PID %d (%S), error %d, ntstatus %X
CheckProc: cannot get modules list for PID %d (%S), error %d, ntstatus %X
CheckProc: cannot get modules list for PID %d (%S), error %d
CheckProc: cannot get modules list for PID %d (%S), error %d
CheckProcess PID %d (%S):
CheckProcess PID %d (%S):
PEB.PostProcessInitRoutine: %p %s
PEB.PostProcessInitRoutine: %p %s
PEB.PostProcessInitRoutine: %p UNKNOWN
PEB.PostProcessInitRoutine: %p UNKNOWN
PEB.pShimData: %p
PEB.pShimData: %p
PEB.AppCompat: %p
PEB.AppCompat: %p
PEB.FastPebLockRoutine: %p %s
PEB.FastPebLockRoutine: %p %s
PEB.FastPebLockRoutine: %p UNKNOWN
PEB.FastPebLockRoutine: %p UNKNOWN
PEB.FastPebUnlockRoutine: %p %s
PEB.FastPebUnlockRoutine: %p %s
PEB.FastPebUnlockRoutine: %p UNKNOWN
PEB.FastPebUnlockRoutine: %p UNKNOWN
Module: %s at %p
Module: %s at %p
Cannot read %s, PID %d, error %d
Cannot read %s, PID %d, error %d
PID %d: LSA SP %s has %d patched functions in SECPKG_FUNCTION_TABLE:
PID %d: LSA SP %s has %d patched functions in SECPKG_FUNCTION_TABLE:
PID %d: ncrypt has %d patched functions
PID %d: ncrypt has %d patched functions
PID %d: mswsock has %d patched functions in SockProcTable
PID %d: mswsock has %d patched functions in SockProcTable
PID %d: mswsock has %d patched functions in NspVector
PID %d: mswsock has %d patched functions in NspVector
PID %d: mswsock has %d patched MSAFD functions
PID %d: mswsock has %d patched MSAFD functions
SHAREDINFO.aheList: %p
SHAREDINFO.aheList: %p
PID %d: ntdsa has %d patched functions
PID %d: ntdsa has %d patched functions
PID %d - ole32 hooked by %s
PID %d - ole32 hooked by %s
PID %d - ole32 hooked by unknown module, addr %p
PID %d - ole32 hooked by unknown module, addr %p
PID %d: rpcrt4 has %d patched functions
PID %d: rpcrt4 has %d patched functions
PID %d: basesrv has %d patched user functions
PID %d: basesrv has %d patched user functions
PID %d: winsrv has %d patched user functions
PID %d: winsrv has %d patched user functions
PID %d: winsrv has %d patched cons functions
PID %d: winsrv has %d patched cons functions
PID %d: lsasrv has %d patched functions
PID %d: lsasrv has %d patched functions
PID %d: lsasrv has %d patched functions in LsapSspiExtension
PID %d: lsasrv has %d patched functions in LsapSspiExtension
PID %d: lsasrv has %d patched functions in LsapLookupExtension
PID %d: lsasrv has %d patched functions in LsapLookupExtension
PID %d: lsasrv has %d patched functions in LsapLsasrvIfTable
PID %d: lsasrv has %d patched functions in LsapLsasrvIfTable
Cannot alloc %X bytes for EAT checking of %s, PID %d
Cannot alloc %X bytes for EAT checking of %s, PID %d
Cannot read EAT of %s, PID %d
Cannot read EAT of %s, PID %d
Cannot alloc %X bytes for checking section %s of %s, PID %d
Cannot alloc %X bytes for checking section %s of %s, PID %d
Cannot read section %s content %X bytes of %s, PID %d
Cannot read section %s content %X bytes of %s, PID %d
Cannot make section %s of %s, PID %d
Cannot make section %s of %s, PID %d
Module %s section %s has %X patched bytes, PID %d
Module %s section %s has %X patched bytes, PID %d
PID %d: user32 has %d patched imm32 functions
PID %d: user32 has %d patched imm32 functions
PID %d: advapi32 has %d patched functions
PID %d: advapi32 has %d patched functions
PID %d: kernel32 has %d patched functions
PID %d: kernel32 has %d patched functions
ShimHandler[%d]: %p %s
ShimHandler[%d]: %p %s
ShimHandler[%d]: %p UNKNOWN, located at %p
ShimHandler[%d]: %p UNKNOWN, located at %p
ApplicationRecoveryCallback: %s (%p)
ApplicationRecoveryCallback: %s (%p)
%s, PID %d:
%s, PID %d:
Cannot alloc %X bytes for IAT checking of %s, PID %d
Cannot alloc %X bytes for IAT checking of %s, PID %d
Cannot read IAT (size %X at %p) of %s, PID %d
Cannot read IAT (size %X at %p) of %s, PID %d
Cannot find function %s.%s for module %s process %d
Cannot find function %s.%s for module %s process %d
Cannot find function %s.%d for module %s process %d
Cannot find function %s.%d for module %s process %d
IAT Patched %s.%s in module %s process %d by %s
IAT Patched %s.%s in module %s process %d by %s
IAT Patched %s.%s in module %s process %d, addr %p
IAT Patched %s.%s in module %s process %d, addr %p
IAT Patched %s.%d in module %s process %d by %s
IAT Patched %s.%d in module %s process %d by %s
IAT Patched %s.%d in module %s process %d
IAT Patched %s.%d in module %s process %d
Cannot alloc %X bytes for delayed IAT checking of %s, PID %d
Cannot alloc %X bytes for delayed IAT checking of %s, PID %d
Cannot read delayed IAT (size %X at %p) of %s, PID %d
Cannot read delayed IAT (size %X at %p) of %s, PID %d
Cannot find delayed function %s.%s for module %s process %d
Cannot find delayed function %s.%s for module %s process %d
Cannot find delayed function %s.%d for module %s process %d
Cannot find delayed function %s.%d for module %s process %d
LdrpDllNotificationList: %d
LdrpDllNotificationList: %d
%p %s
%p %s
Read %d QueuedWorkerItems:
Read %d QueuedWorkerItems:
[%d] %p %s
[%d] %p %s
check_drivers_reinit: cannot read size of list, error %d, status %X
check_drivers_reinit: cannot read size of list, error %d, status %X
check_drivers_reinit: cannot read size of list, error %d
check_drivers_reinit: cannot read size of list, error %d
check_drivers_reinit: cannot alloc %X bytes
check_drivers_reinit: cannot alloc %X bytes
check_drivers_reinit: cannot read list, error %d, ntstatus %X
check_drivers_reinit: cannot read list, error %d, ntstatus %X
check_drivers_reinit: cannot read list, error %d
check_drivers_reinit: cannot read list, error %d
[%d] Drv %p %s routine %p %s
[%d] Drv %p %s routine %p %s
read_shutdown_notificators: cannot read size of %s, error %d, status %X
read_shutdown_notificators: cannot read size of %s, error %d, status %X
read_shutdown_notificators: cannot read size of %s, error %d
read_shutdown_notificators: cannot read size of %s, error %d
read_shutdown_notificators: cannot alloc %X bytes
read_shutdown_notificators: cannot alloc %X bytes
read_shutdown_notificators: cannot read %s, error %d, ntstatus %X
read_shutdown_notificators: cannot read %s, error %d, ntstatus %X
read_shutdown_notificators: cannot read %s, error %d
read_shutdown_notificators: cannot read %s, error %d
[%d] DevObj %p Drv %p (addr %p) %s
[%d] DevObj %p Drv %p (addr %p) %s
[%d] DevObj %p Drv %p %s
[%d] DevObj %p Drv %p %s
MailSlot: %S, server %d (%S)
MailSlot: %S, server %d (%S)
MailSlot: %S, server %d
MailSlot: %S, server %d
NamedPipe: %S, server %d (%S)
NamedPipe: %S, server %d (%S)
NamedPipe: %S, server %d
NamedPipe: %S, server %d
Flags: %X, server %d (%S)
Flags: %X, server %d (%S)
Flags: %X, creator %d, server %d
Flags: %X, creator %d, server %d
Flags: %X, server %d
Flags: %X, server %d
Endpoints: %d
Endpoints: %d
Endpoint %S PID %d (%S):
Endpoint %S PID %d (%S):
Endpoint %S:
Endpoint %S:
RPC controls: %d
RPC controls: %d
%S: %S
%S: %S
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d
Cannot load kernel %s
Cannot load kernel %s
Unknown scheduler: ReadySummary %X DispatcherReadyListHead %X
Unknown scheduler: ReadySummary %X DispatcherReadyListHead %X
Unknown scheduler: ReadySummary %X DeferredReadyListHead %X
Unknown scheduler: ReadySummary %X DeferredReadyListHead %X
Unknown scheduler: ReadySummary %X
Unknown scheduler: ReadySummary %X
Readed %d threads, total %d
Readed %d threads, total %d
Thread %p ProcID %X ThreadID %X Win32Thread %p %s
Thread %p ProcID %X ThreadID %X Win32Thread %p %s
Thread %p ProcID %X ThreadID %X Priority %d Win32Thread %p
Thread %p ProcID %X ThreadID %X Priority %d Win32Thread %p
Thread %p ProcID %X ThreadID %X %s
Thread %p ProcID %X ThreadID %X %s
Thread %p ProcID %X ThreadID %X Priority %d
Thread %p ProcID %X ThreadID %X Priority %d
reading count of threads on processor %d failed, error %X
reading count of threads on processor %d failed, error %X
%d threads
%d threads
reading of threads on processor %d failed, error %X
reading of threads on processor %d failed, error %X
Scheduler index %d
Scheduler index %d
reading count of threads failed, error %X
reading count of threads failed, error %X
reading of threads failed, error %X
reading of threads failed, error %X
Cannot find ETHREAD.ServiceTable
Cannot find ETHREAD.ServiceTable
Unknown version of ETHREAD, offset %X
Unknown version of ETHREAD, offset %X
Cannot alloc %X bytes for ProcessesAndThreadsInformation
Cannot alloc %X bytes for ProcessesAndThreadsInformation
Cannot realloc %X bytes for ProcessesAndThreadsInformation
Cannot realloc %X bytes for ProcessesAndThreadsInformation
ProcessesAndThreadsInformation failed, error %X
ProcessesAndThreadsInformation failed, error %X
read_sdt for threadID %X failed, error %d, status %X
read_sdt for threadID %X failed, error %d, status %X
read_sdt for threadID %X failed, error %d
read_sdt for threadID %X failed, error %d
ProcessID %X (%S) ThreadID %X SDT %p %s
ProcessID %X (%S) ThreadID %X SDT %p %s
ProcessID %X ThreadID %X SDT %p %s
ProcessID %X ThreadID %X SDT %p %s
read_thread_token for threadID %X failed, error %d, status %X
read_thread_token for threadID %X failed, error %d, status %X
read_thread_token for threadID %X failed, error %d
read_thread_token for threadID %X failed, error %d
ProcessID %X (%S) ThreadID %X token %p ImpersonationLevel %d
ProcessID %X (%S) ThreadID %X token %p ImpersonationLevel %d
ProcessID %X ThreadID %X token %p ImpersonationLevel %d
ProcessID %X ThreadID %X token %p ImpersonationLevel %d
Cannot detect ETHREAD.StartAddress
Cannot detect ETHREAD.StartAddress
Unknown kernel %s, StartAddress %X, IrpList %X, StackLimit %X, StackBase %X
Unknown kernel %s, StartAddress %X, IrpList %X, StackLimit %X, StackBase %X
Unknown kernel %s, StartAddress %X, StackLimit %X, StackBase %X
Unknown kernel %s, StartAddress %X, StackLimit %X, StackBase %X
Unknown kernel %s, StartAddress %X, IrpList %X
Unknown kernel %s, StartAddress %X, IrpList %X
Unknown kernel %s, StartAddress %X
Unknown kernel %s, StartAddress %X
Cannot read count of system threads, ntstatus %X
Cannot read count of system threads, ntstatus %X
Cannot alloc %d bytes
Cannot alloc %d bytes
Cannot read system threads, ntstatus %X
Cannot read system threads, ntstatus %X
%d System Threads
%d System Threads
Thread %p Start %p %c stack %p limit %p %s
Thread %p Start %p %c stack %p limit %p %s
read IPSec status failed, error %d, status %X
read IPSec status failed, error %d, status %X
read IPSec status failed, error %d
read IPSec status failed, error %d
IPSec status %X
IPSec status %X
IPSecHandler: %p %s
IPSecHandler: %p %s
IPSecQueryStatus: %p %s
IPSecQueryStatus: %p %s
IPSecSendCmplt: %p %s
IPSecSendCmplt: %p %s
IPSecNdisStatus: %p %s
IPSecNdisStatus: %p %s
IPSecRcvFWPacket: %p %s
IPSecRcvFWPacket: %p %s
check_tdi_pnp_clnts: cannot read size of clnts list, error %d, ntstatus %X
check_tdi_pnp_clnts: cannot read size of clnts list, error %d, ntstatus %X
check_tdi_pnp_clnts: cannot read size of clnts list, error %d
check_tdi_pnp_clnts: cannot read size of clnts list, error %d
check_tdi_pnp_clnts: cannot alloc %X bytes
check_tdi_pnp_clnts: cannot alloc %X bytes
check_tdi_pnp_clnts: cannot read clnts list, error %d, ntstatus %X
check_tdi_pnp_clnts: cannot read clnts list, error %d, ntstatus %X
check_tdi_pnp_clnts: cannot read clnts list, error %d
check_tdi_pnp_clnts: cannot read clnts list, error %d
TDI PnP clients: %d (readed %d)
TDI PnP clients: %d (readed %d)
[%d]: version %X %S
[%d]: version %X %S
PnPPowerHandler: %p %s
PnPPowerHandler: %p %s
BindHandler: %p %s
BindHandler: %p %s
UnBindHandler: %p %s
UnBindHandler: %p %s
AddAddressHandler: %p %s
AddAddressHandler: %p %s
DelAddressHandler: %p %s
DelAddressHandler: %p %s
Microsoft-Windows-Windows Firewall With Advanced Security
Microsoft-Windows-Windows Firewall With Advanced Security
Microsoft-Windows-Kernel-Boot
Microsoft-Windows-Kernel-Boot
Microsoft-Windows-EQoS
Microsoft-Windows-EQoS
Microsoft-Windows-XWizards
Microsoft-Windows-XWizards
ASP.NET Events
ASP.NET Events
Microsoft-Windows-UIRibbon
Microsoft-Windows-UIRibbon
Microsoft-Windows-WPD-CompositeClassDriver
Microsoft-Windows-WPD-CompositeClassDriver
Microsoft-Windows-Wired-AutoConfig
Microsoft-Windows-Wired-AutoConfig
Microsoft-Windows-PrintService
Microsoft-Windows-PrintService
Microsoft-Windows-ApplicationExperience-LookupServiceTrigger
Microsoft-Windows-ApplicationExperience-LookupServiceTrigger
Microsoft-Windows-IDCRL
Microsoft-Windows-IDCRL
Microsoft-Windows-MPS-DRV
Microsoft-Windows-MPS-DRV
Microsoft-Windows-P2P-Mesh
Microsoft-Windows-P2P-Mesh
Microsoft-Windows-TabletPC-MathRecognizer
Microsoft-Windows-TabletPC-MathRecognizer
Microsoft-Windows-Spell-Checking
Microsoft-Windows-Spell-Checking
Microsoft-Windows-Fax
Microsoft-Windows-Fax
Microsoft-Windows-GroupPolicy
Microsoft-Windows-GroupPolicy
Microsoft-Windows-Crashdump
Microsoft-Windows-Crashdump
Microsoft-Windows-PrintSpooler
Microsoft-Windows-PrintSpooler
Microsoft-Windows-LanguagePackSetup
Microsoft-Windows-LanguagePackSetup
Microsoft-Windows-OneX
Microsoft-Windows-OneX
Microsoft-Windows-OfflineFiles-CscApi
Microsoft-Windows-OfflineFiles-CscApi
Microsoft-Windows-ADSI
Microsoft-Windows-ADSI
Microsoft-Windows-Dhcp-Client
Microsoft-Windows-Dhcp-Client
Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Microsoft-Windows-NlaSvc
Microsoft-Windows-NlaSvc
Microsoft-Windows-Diagnosis-MSDE
Microsoft-Windows-Diagnosis-MSDE
Microsoft-Windows-SpoolerWin32SPL
Microsoft-Windows-SpoolerWin32SPL
Microsoft-Windows-SPB-ClassExtension
Microsoft-Windows-SPB-ClassExtension
Microsoft-Windows-Kernel-Memory
Microsoft-Windows-Kernel-Memory
Microsoft-Windows-Application Server-Applications
Microsoft-Windows-Application Server-Applications
Microsoft-Windows-MUI
Microsoft-Windows-MUI
Microsoft-Windows-P2P-Collab
Microsoft-Windows-P2P-Collab
Microsoft-Windows-Security-Netlogon
Microsoft-Windows-Security-Netlogon
Microsoft-Windows-SQM-Events
Microsoft-Windows-SQM-Events
Microsoft-Windows-USB-USBPORT
Microsoft-Windows-USB-USBPORT
Microsoft-Windows-SendTo
Microsoft-Windows-SendTo
Microsoft-Windows-AIT
Microsoft-Windows-AIT
Microsoft-Windows-P2P-CRP
Microsoft-Windows-P2P-CRP
PrintFilterPipelineSvc_ObjectsGuid
PrintFilterPipelineSvc_ObjectsGuid
Microsoft-Windows-IME-JPPRED
Microsoft-Windows-IME-JPPRED
Microsoft-Windows-WMP
Microsoft-Windows-WMP
Microsoft-Windows-Eqos-SQM-Provider
Microsoft-Windows-Eqos-SQM-Provider
MSDADIAG.ETW
MSDADIAG.ETW
Microsoft-Windows-Processor-Aggregator
Microsoft-Windows-Processor-Aggregator
Microsoft-Windows-ErrorReportingConsole
Microsoft-Windows-ErrorReportingConsole
Microsoft-Windows-SmartCard-TPM-VCard-Module
Microsoft-Windows-SmartCard-TPM-VCard-Module
Microsoft-Windows-User Profiles Service
Microsoft-Windows-User Profiles Service
Microsoft-Windows-Crypto-CNG
Microsoft-Windows-Crypto-CNG
Microsoft-Windows-LinkLayerDiscoveryProtocol
Microsoft-Windows-LinkLayerDiscoveryProtocol
Microsoft-Windows-TaskbarCPL
Microsoft-Windows-TaskbarCPL
Microsoft-Windows-Networking-Correlation
Microsoft-Windows-Networking-Correlation
Microsoft-Windows-RestartManager
Microsoft-Windows-RestartManager
Microsoft-Windows-WMPDMCCore
Microsoft-Windows-WMPDMCCore
Microsoft-Windows-TCPIP
Microsoft-Windows-TCPIP
Microsoft-Windows-MSDTC
Microsoft-Windows-MSDTC
Microsoft-Windows-Resources-MrmBc
Microsoft-Windows-Resources-MrmBc
Microsoft-Windows-Time-Service
Microsoft-Windows-Time-Service
Microsoft-Windows-HomeGroup-ProviderService
Microsoft-Windows-HomeGroup-ProviderService
Microsoft-Windows-DriverFrameworks-UserMode
Microsoft-Windows-DriverFrameworks-UserMode
Microsoft-Windows-Runtime-Networking
Microsoft-Windows-Runtime-Networking
Microsoft-Windows-Network-Connection-Broker
Microsoft-Windows-Network-Connection-Broker
Microsoft-Windows-Shell-AppWizCpl
Microsoft-Windows-Shell-AppWizCpl
Microsoft-Windows-PDC
Microsoft-Windows-PDC
Microsoft-Windows-Biometrics
Microsoft-Windows-Biometrics
Microsoft-Windows-IME-SCDICCOMPILER
Microsoft-Windows-IME-SCDICCOMPILER
Microsoft-Windows-Wininit
Microsoft-Windows-Wininit
Microsoft-Windows-Dwm-Dwm
Microsoft-Windows-Dwm-Dwm
Microsoft-Windows-Photo-Image-Codec
Microsoft-Windows-Photo-Image-Codec
Microsoft-Windows-TaskScheduler
Microsoft-Windows-TaskScheduler
Microsoft-Windows-osk
Microsoft-Windows-osk
Microsoft-Windows-Kernel-PowerTrigger
Microsoft-Windows-Kernel-PowerTrigger
Microsoft-Windows-EventLog-WMIProvider
Microsoft-Windows-EventLog-WMIProvider
Microsoft-Windows-IME-OEDCompiler
Microsoft-Windows-IME-OEDCompiler
Microsoft-Windows-WER-SystemErrorReporting
Microsoft-Windows-WER-SystemErrorReporting
Microsoft-Windows-Deplorch
Microsoft-Windows-Deplorch
Microsoft-Windows-SPB-HIDI2C
Microsoft-Windows-SPB-HIDI2C
Microsoft-Windows-UxTheme
Microsoft-Windows-UxTheme
Microsoft-Windows-BfeTriggerProvider
Microsoft-Windows-BfeTriggerProvider
Microsoft-Windows-Media-Streaming
Microsoft-Windows-Media-Streaming
Microsoft-Windows-Remotefs-UTProvider
Microsoft-Windows-Remotefs-UTProvider
Microsoft-Windows-Ntfs-SQM
Microsoft-Windows-Ntfs-SQM
Microsoft-Windows-User-PnP
Microsoft-Windows-User-PnP
Microsoft-Windows-AltTab
Microsoft-Windows-AltTab
Microsoft-Windows-Kernel-StoreMgr
Microsoft-Windows-Kernel-StoreMgr
Microsoft-Windows-WindowsColorSystem
Microsoft-Windows-WindowsColorSystem
Microsoft-Windows-RemoteDesktopServices-RemoteFX-VM-User-Mode-Transport
Microsoft-Windows-RemoteDesktopServices-RemoteFX-VM-User-Mode-Transport
Microsoft-Windows-MSMPEG2ADEC
Microsoft-Windows-MSMPEG2ADEC
Microsoft-Windows-TerminalServices-PnPDevices
Microsoft-Windows-TerminalServices-PnPDevices
Microsoft-Windows-GettingStarted
Microsoft-Windows-GettingStarted
Microsoft-Windows-Narrator
Microsoft-Windows-Narrator
Windows Wininit Trace
Windows Wininit Trace
Microsoft-Windows-FileHistory-UI
Microsoft-Windows-FileHistory-UI
Microsoft-Windows-MediaFoundation-PlayAPI
Microsoft-Windows-MediaFoundation-PlayAPI
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Microsoft-Windows-BitLocker-Driver-Performance
Microsoft-Windows-BitLocker-Driver-Performance
Microsoft-Windows-PerfProc
Microsoft-Windows-PerfProc
Microsoft-Windows-Resource-Leak-Diagnostic
Microsoft-Windows-Resource-Leak-Diagnostic
Microsoft-Windows-WebServices
Microsoft-Windows-WebServices
Microsoft-Windows-FileHistory-Service
Microsoft-Windows-FileHistory-Service
Microsoft-Windows-MediaEngine
Microsoft-Windows-MediaEngine
Microsoft-Windows-StartupRepair
Microsoft-Windows-StartupRepair
Microsoft-Windows-Security-IdentityStore
Microsoft-Windows-Security-IdentityStore
Microsoft-Windows-IME-SCSetting
Microsoft-Windows-IME-SCSetting
Microsoft-Windows-FileHistory-EventListener
Microsoft-Windows-FileHistory-EventListener
Microsoft-Windows-Program-Compatibility-Assistant
Microsoft-Windows-Program-Compatibility-Assistant
Microsoft-Windows-DesktopActivityModerator
Microsoft-Windows-DesktopActivityModerator
Microsoft-Windows-MemoryDiagnostics-Schedule
Microsoft-Windows-MemoryDiagnostics-Schedule
Microsoft-Windows-FileHistory-Engine
Microsoft-Windows-FileHistory-Engine
Microsoft-Windows-PerfDisk
Microsoft-Windows-PerfDisk
Microsoft-Windows-OOBE-Machine-Core
Microsoft-Windows-OOBE-Machine-Core
Microsoft-Windows-WLAN-AutoConfig
Microsoft-Windows-WLAN-AutoConfig
Microsoft-Windows-FileHistory-ConfigManager
Microsoft-Windows-FileHistory-ConfigManager
Microsoft-Windows-Search-ProfileNotify
Microsoft-Windows-Search-ProfileNotify
Microsoft-Windows-PerfCtrs
Microsoft-Windows-PerfCtrs
UMPass Driver Trace
UMPass Driver Trace
Microsoft-Windows-FileHistory-Catalog
Microsoft-Windows-FileHistory-Catalog
Microsoft-Windows-WlanDlg
Microsoft-Windows-WlanDlg
Microsoft-Windows-CDROM
Microsoft-Windows-CDROM
Microsoft-Windows-Crypto-NCrypt
Microsoft-Windows-Crypto-NCrypt
Certificate Services Client CredentialRoaming Trace
Certificate Services Client CredentialRoaming Trace
Microsoft-Windows-CredUI
Microsoft-Windows-CredUI
Windows Firewall Service
Windows Firewall Service
Microsoft-Windows-FileHistory-Core
Microsoft-Windows-FileHistory-Core
Microsoft-Windows-Direct3D11
Microsoft-Windows-Direct3D11
Microsoft-Windows-DirectoryServices-Deployment
Microsoft-Windows-DirectoryServices-Deployment
Microsoft-Windows-All-User-Install-Agent
Microsoft-Windows-All-User-Install-Agent
Microsoft-Windows-Kernel-Licensing-StartServiceTrigger
Microsoft-Windows-Kernel-Licensing-StartServiceTrigger
Microsoft-Windows-ServerManager-ManagementProvider
Microsoft-Windows-ServerManager-ManagementProvider
Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider
Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider
Microsoft-Windows-IIS-W3SVC-WP
Microsoft-Windows-IIS-W3SVC-WP
Microsoft-Windows-TerminalServices-MediaRedirection-DShow
Microsoft-Windows-TerminalServices-MediaRedirection-DShow
Microsoft-Windows-Rdms-UI
Microsoft-Windows-Rdms-UI
Microsoft-Windows-Feedback-Service-TriggerProvider
Microsoft-Windows-Feedback-Service-TriggerProvider
Microsoft-Windows-Eventlog
Microsoft-Windows-Eventlog
Microsoft-Windows-CodeIntegrity
Microsoft-Windows-CodeIntegrity
Microsoft-Windows-WPDClassInstaller
Microsoft-Windows-WPDClassInstaller
Microsoft-Windows-NetworkAccessProtection
Microsoft-Windows-NetworkAccessProtection
Microsoft-Windows-UIAutomationCore
Microsoft-Windows-UIAutomationCore
Microsoft-Windows-StartLmhosts
Microsoft-Windows-StartLmhosts
Microsoft-Windows-IME-Broker
Microsoft-Windows-IME-Broker
Microsoft-Windows-Kernel-Process
Microsoft-Windows-Kernel-Process
Microsoft-Windows-CertificateServicesClient
Microsoft-Windows-CertificateServicesClient
Microsoft-Windows-AppXDeployment
Microsoft-Windows-AppXDeployment
Microsoft-Windows-Shell-Core
Microsoft-Windows-Shell-Core
Microsoft-Windows-Anytime-Upgrade
Microsoft-Windows-Anytime-Upgrade
Microsoft-Windows-PCI
Microsoft-Windows-PCI
Microsoft-Windows-WPD-MTPBT
Microsoft-Windows-WPD-MTPBT
Microsoft-Windows-CertificationAuthorityClient-CertCli
Microsoft-Windows-CertificationAuthorityClient-CertCli
Microsoft-Windows-Srv2
Microsoft-Windows-Srv2
Microsoft-Windows-TunnelDriver-SQM-Provider
Microsoft-Windows-TunnelDriver-SQM-Provider
Microsoft-Windows-Security-Licensing-SLC
Microsoft-Windows-Security-Licensing-SLC
Microsoft-Windows-ATAPort
Microsoft-Windows-ATAPort
Microsoft-Windows-Recovery
Microsoft-Windows-Recovery
Microsoft-Windows-GenericRoaming
Microsoft-Windows-GenericRoaming
Microsoft-Windows-Sdbus-SQM
Microsoft-Windows-Sdbus-SQM
Microsoft-Windows-DirectComposition
Microsoft-Windows-DirectComposition
Microsoft-Windows-P2PIMSvc
Microsoft-Windows-P2PIMSvc
Microsoft-Windows-WCN-Config-Registrar
Microsoft-Windows-WCN-Config-Registrar
Microsoft-Windows-WPD-API
Microsoft-Windows-WPD-API
Microsoft-Windows-P2P-PNRP
Microsoft-Windows-P2P-PNRP
Microsoft-Windows-DeviceUx
Microsoft-Windows-DeviceUx
Windows Mobile Performance Hooks
Windows Mobile Performance Hooks
Microsoft-Windows-ProcessStateManager
Microsoft-Windows-ProcessStateManager
Windows Connect Now
Windows Connect Now
Microsoft-Windows-Networking-RealTimeCommunication
Microsoft-Windows-Networking-RealTimeCommunication
Microsoft-Windows-EventSystem
Microsoft-Windows-EventSystem
Microsoft-Windows-Spaceport
Microsoft-Windows-Spaceport
Windows Mobile Remote API
Windows Mobile Remote API
Microsoft-Windows-Dhcp-Nap-Enforcement-Client
Microsoft-Windows-Dhcp-Nap-Enforcement-Client
Microsoft-Windows-WinNat
Microsoft-Windows-WinNat
Windows Mobile AirSync Engine 2
Windows Mobile AirSync Engine 2
Microsoft-Windows-WCN-Config-Registrar-Secure
Microsoft-Windows-WCN-Config-Registrar-Secure
Windows Mobile AirSync Engine 1
Windows Mobile AirSync Engine 1
Microsoft-Windows-Security-Kerberos
Microsoft-Windows-Security-Kerberos
Windows Mobile ActiveSync Engine
Windows Mobile ActiveSync Engine
Microsoft-Windows-WSC-SRV
Microsoft-Windows-WSC-SRV
Microsoft-Windows-Eventlog-ForwardPlugin
Microsoft-Windows-Eventlog-ForwardPlugin
Windows Mobile Serial Connectivity
Windows Mobile Serial Connectivity
Microsoft-Windows-TerminalServices-SessionBroker-Client
Microsoft-Windows-TerminalServices-SessionBroker-Client
Microsoft-Windows-WMPNSS-PublicAPI
Microsoft-Windows-WMPNSS-PublicAPI
Windows Mobile Desktop Passthrough
Windows Mobile Desktop Passthrough
Microsoft-Windows-RPC-Events
Microsoft-Windows-RPC-Events
Microsoft-Windows-LanguageProfile
Microsoft-Windows-LanguageProfile
Microsoft-Windows-Anytime-Upgrade-Events
Microsoft-Windows-Anytime-Upgrade-Events
Microsoft-Windows-Management-UI
Microsoft-Windows-Management-UI
Microsoft-Windows-SMBClient
Microsoft-Windows-SMBClient
Microsoft-Windows-TerminalServices-RdpSoundDriver
Microsoft-Windows-TerminalServices-RdpSoundDriver
Microsoft-Windows-Dwm-Api
Microsoft-Windows-Dwm-Api
Microsoft-Windows-QoS-qWAVE
Microsoft-Windows-QoS-qWAVE
Microsoft-Windows-Kernel-Tm-Trigger
Microsoft-Windows-Kernel-Tm-Trigger
Microsoft-Windows-IPNAT
Microsoft-Windows-IPNAT
Microsoft-Windows-NetworkBridge
Microsoft-Windows-NetworkBridge
Microsoft-Windows-MPS-CLNT
Microsoft-Windows-MPS-CLNT
Microsoft-Windows-Diagnosis-Scheduled
Microsoft-Windows-Diagnosis-Scheduled
Microsoft-Windows-WMPNSS-Service
Microsoft-Windows-WMPNSS-Service
Microsoft-Windows-DxpTaskRingtone
Microsoft-Windows-DxpTaskRingtone
Microsoft-Windows-Kernel-AppCompat
Microsoft-Windows-Kernel-AppCompat
Microsoft-Windows-TimeBroker
Microsoft-Windows-TimeBroker
Microsoft-Windows-DeviceConfidence
Microsoft-Windows-DeviceConfidence
Microsoft-Windows-Shell-Shwebsvc
Microsoft-Windows-Shell-Shwebsvc
Microsoft-Windows-Diagnostics-Performance
Microsoft-Windows-Diagnostics-Performance
Windows NetworkMap Trace
Windows NetworkMap Trace
Microsoft-Windows-TerminalServices-Printers
Microsoft-Windows-TerminalServices-Printers
Microsoft-Windows-AppLocker
Microsoft-Windows-AppLocker
Microsoft-Windows-Audio
Microsoft-Windows-Audio
Microsoft-Windows-LLTD-MapperIO
Microsoft-Windows-LLTD-MapperIO
Microsoft-Windows-HotspotAuth
Microsoft-Windows-HotspotAuth
Microsoft-Windows-Firewall-CPL
Microsoft-Windows-Firewall-CPL
Microsoft-Windows-Kernel-IoTrace
Microsoft-Windows-Kernel-IoTrace
Microsoft-Windows-Perflib
Microsoft-Windows-Perflib
Microsoft-Windows-BootUX
Microsoft-Windows-BootUX
Microsoft-Windows-WMPDMCUI
Microsoft-Windows-WMPDMCUI
Microsoft-Windows-Disk
Microsoft-Windows-Disk
Microsoft-Windows-IME-JPLMP
Microsoft-Windows-IME-JPLMP
Microsoft-Windows-Security-SPP-UX-Notifications
Microsoft-Windows-Security-SPP-UX-Notifications
Microsoft-Windows-TerminalServices-ClientActiveXCore
Microsoft-Windows-TerminalServices-ClientActiveXCore
Microsoft-Windows-IIS-IISReset
Microsoft-Windows-IIS-IISReset
Microsoft-Windows-WindowsUIImmersive
Microsoft-Windows-WindowsUIImmersive
Windows Firewall Control Panel
Windows Firewall Control Panel
Microsoft-Windows-DeviceSetupManager
Microsoft-Windows-DeviceSetupManager
Microsoft-Windows-EnrollmentPolicyWebService
Microsoft-Windows-EnrollmentPolicyWebService
Microsoft-Windows-IME-Roaming
Microsoft-Windows-IME-Roaming
Microsoft-Windows-SetupQueue
Microsoft-Windows-SetupQueue
Microsoft-Windows-SmartCard-Audit
Microsoft-Windows-SmartCard-Audit
Microsoft-Windows-Servicing
Microsoft-Windows-Servicing
Microsoft-Windows-ACL-UI
Microsoft-Windows-ACL-UI
Microsoft-Windows-WWAN-CFE
Microsoft-Windows-WWAN-CFE
Microsoft-Windows-FCRegSvc
Microsoft-Windows-FCRegSvc
Microsoft-Windows-IIS-IisMetabaseAudit
Microsoft-Windows-IIS-IisMetabaseAudit
Microsoft-Windows-Kernel-WDI
Microsoft-Windows-Kernel-WDI
Microsoft-Windows-TabletPC-MathInput
Microsoft-Windows-TabletPC-MathInput
Microsoft-Windows-Kernel-General
Microsoft-Windows-Kernel-General
Windows Media Player Trace
Windows Media Player Trace
Microsoft-Windows-DxpTaskDLNA
Microsoft-Windows-DxpTaskDLNA
Microsoft-Windows-User Profiles General
Microsoft-Windows-User Profiles General
Microsoft-Windows-Kernel-WSService-StartServiceTrigger
Microsoft-Windows-Kernel-WSService-StartServiceTrigger
Microsoft-Windows-WebAuth
Microsoft-Windows-WebAuth
Microsoft-Windows-API-Tracing
Microsoft-Windows-API-Tracing
Microsoft-Windows-FunctionDiscovery
Microsoft-Windows-FunctionDiscovery
Microsoft-Windows-StickyNotes
Microsoft-Windows-StickyNotes
Microsoft-Windows-WCN-WscEapPeer-Trace
Microsoft-Windows-WCN-WscEapPeer-Trace
Microsoft-Windows-QoS-WMI-Diag
Microsoft-Windows-QoS-WMI-Diag
Microsoft-Windows-NetworkProvisioning
Microsoft-Windows-NetworkProvisioning
Microsoft-Windows-Network-DataUsage
Microsoft-Windows-Network-DataUsage
Microsoft-Windows-AppSruProv
Microsoft-Windows-AppSruProv
Microsoft-Windows-WebcamExperience
Microsoft-Windows-WebcamExperience
Microsoft-Windows-EaseOfAccess
Microsoft-Windows-EaseOfAccess
Microsoft-Windows-Spellchecking-Host
Microsoft-Windows-Spellchecking-Host
Microsoft-Windows-IME-CandidateUI
Microsoft-Windows-IME-CandidateUI
Microsoft-Windows-TPM-WMI
Microsoft-Windows-TPM-WMI
Microsoft-Windows-Security-SPP
Microsoft-Windows-Security-SPP
Microsoft-Windows-DirectShow-KernelSupport
Microsoft-Windows-DirectShow-KernelSupport
Microsoft-Windows-Diagnosis-AdvancedTaskManager
Microsoft-Windows-Diagnosis-AdvancedTaskManager
Microsoft-Windows-ThemeCPL
Microsoft-Windows-ThemeCPL
Windows Mobile Co-installer
Windows Mobile Co-installer
Microsoft-Windows-MPRMSG
Microsoft-Windows-MPRMSG
Microsoft-Windows-EnhancedStorage-EhStorCertDrv
Microsoft-Windows-EnhancedStorage-EhStorCertDrv
Microsoft-Windows-NdisImPlatformEventProvider
Microsoft-Windows-NdisImPlatformEventProvider
Microsoft-Windows-FunctionDiscoveryHost
Microsoft-Windows-FunctionDiscoveryHost
Microsoft-Windows-MediaFoundation-MSVideoDSP
Microsoft-Windows-MediaFoundation-MSVideoDSP
Microsoft-Windows-IME-JPTIP
Microsoft-Windows-IME-JPTIP
Windows Kernel Trace
Windows Kernel Trace
Microsoft-SQLServerDataTools
Microsoft-SQLServerDataTools
Microsoft-Windows-ASN1
Microsoft-Windows-ASN1
Microsoft-Windows-Crypto-BCrypt
Microsoft-Windows-Crypto-BCrypt
Microsoft-Windows-HealthCenterCPL
Microsoft-Windows-HealthCenterCPL
Microsoft-Windows-XAML
Microsoft-Windows-XAML
Microsoft-Windows-PDFReader
Microsoft-Windows-PDFReader
Microsoft-Windows-TerminalServices-ServerUSBDevices
Microsoft-Windows-TerminalServices-ServerUSBDevices
Microsoft-Windows-WWAN-SVC-EVENTS
Microsoft-Windows-WWAN-SVC-EVENTS
Microsoft-Windows-Search-ProtocolHandlers
Microsoft-Windows-Search-ProtocolHandlers
Microsoft-Windows-IdCtrls
Microsoft-Windows-IdCtrls
Microsoft-Windows-User-ControlPanel
Microsoft-Windows-User-ControlPanel
Microsoft-Windows-Runtime-Media
Microsoft-Windows-Runtime-Media
Microsoft-Windows-CAPI2
Microsoft-Windows-CAPI2
Windows Mobile Sync Handlers
Windows Mobile Sync Handlers
Microsoft-Windows-PowerCfg
Microsoft-Windows-PowerCfg
Microsoft-Windows-SrumTelemetry
Microsoft-Windows-SrumTelemetry
Microsoft-Windows-Base-Filtering-Engine-Connections
Microsoft-Windows-Base-Filtering-Engine-Connections
Microsoft-Windows-Sidebar
Microsoft-Windows-Sidebar
Microsoft-Windows-NDF-HelperClassDiscovery
Microsoft-Windows-NDF-HelperClassDiscovery
Microsoft-Windows-PerfNet
Microsoft-Windows-PerfNet
Microsoft-Windows-PortableDeviceStatusProvider
Microsoft-Windows-PortableDeviceStatusProvider
Microsoft-Windows-TabletPC-Platform-Manipulations
Microsoft-Windows-TabletPC-Platform-Manipulations
Microsoft-Windows-Subsys-SMSS
Microsoft-Windows-Subsys-SMSS
Microsoft-Windows-LDAP-Client
Microsoft-Windows-LDAP-Client
Microsoft-Windows-Security-SPP-UX-GC
Microsoft-Windows-Security-SPP-UX-GC
Microsoft-Windows-Media Center Extender
Microsoft-Windows-Media Center Extender
Microsoft-Windows-DiskDiagnostic
Microsoft-Windows-DiskDiagnostic
Microsoft-Windows-TSF-msutb
Microsoft-Windows-TSF-msutb
Microsoft-Windows-Reliability-Analysis-Agent
Microsoft-Windows-Reliability-Analysis-Agent
{B6501BA0-C61A-C4E6-6FA2-A4E7F8C8E7A0}
{B6501BA0-C61A-C4E6-6FA2-A4E7F8C8E7A0}
Microsoft-Windows-Kernel-Processor-Power
Microsoft-Windows-Kernel-Processor-Power
Microsoft-Windows-NCSI
Microsoft-Windows-NCSI
Microsoft-Windows-NetworkConnectivityStatus
Microsoft-Windows-NetworkConnectivityStatus
Microsoft-Windows-wmvdecod
Microsoft-Windows-wmvdecod
Microsoft-Windows-ServiceTriggerPerfEventProvider
Microsoft-Windows-ServiceTriggerPerfEventProvider
Microsoft-Windows-Service Pack Installer
Microsoft-Windows-Service Pack Installer
Microsoft-Windows-Bluetooth-HidGatt
Microsoft-Windows-Bluetooth-HidGatt
Microsoft-Windows-TabletPC-Platform-Input-Ninput
Microsoft-Windows-TabletPC-Platform-Input-Ninput
Microsoft-Windows-Tcpip-SQM-Provider
Microsoft-Windows-Tcpip-SQM-Provider
Microsoft-Windows-MPS-SRV
Microsoft-Windows-MPS-SRV
Microsoft-Windows-KnownFolders
Microsoft-Windows-KnownFolders
Microsoft-Windows-NAPIPSecEnf
Microsoft-Windows-NAPIPSecEnf
Microsoft-Windows-EnrollmentWebService
Microsoft-Windows-EnrollmentWebService
Microsoft-Windows-Deduplication-Change
Microsoft-Windows-Deduplication-Change
Microsoft-Windows-OfflineFiles-CscFastSync
Microsoft-Windows-OfflineFiles-CscFastSync
Microsoft-Windows-UxInit
Microsoft-Windows-UxInit
Microsoft-Windows-BranchCacheClientEventProvider
Microsoft-Windows-BranchCacheClientEventProvider
Microsoft-Windows-Forwarding
Microsoft-Windows-Forwarding
Microsoft-Windows-RPC-Proxy-LBS
Microsoft-Windows-RPC-Proxy-LBS
Microsoft-Windows-Kernel-Disk
Microsoft-Windows-Kernel-Disk
Microsoft-Windows-TriggerEmulatorProvider
Microsoft-Windows-TriggerEmulatorProvider
Microsoft-Windows-SystemHealthAgent
Microsoft-Windows-SystemHealthAgent
Microsoft-Windows-Memory-Diagnostic-Task-Handler
Microsoft-Windows-Memory-Diagnostic-Task-Handler
Microsoft-Windows-Winsock-WS2HELP
Microsoft-Windows-Winsock-WS2HELP
Microsoft-Windows-ThemeUI
Microsoft-Windows-ThemeUI
Microsoft-Windows-TerminalServices-MediaRedirection
Microsoft-Windows-TerminalServices-MediaRedirection
Microsoft-Windows-TerminalServices-ClientUSBDevices
Microsoft-Windows-TerminalServices-ClientUSBDevices
Microsoft-Windows-TabletPC-CoreInkRecognition
Microsoft-Windows-TabletPC-CoreInkRecognition
Microsoft-Windows-COM
Microsoft-Windows-COM
Microsoft-Windows-PnPMgrTriggerProvider
Microsoft-Windows-PnPMgrTriggerProvider
Microsoft-Windows-LoadPerf
Microsoft-Windows-LoadPerf
Microsoft-Windows-System-Restore
Microsoft-Windows-System-Restore
Microsoft-Windows-UserAccountControl
Microsoft-Windows-UserAccountControl
Microsoft-Windows-Services-Svchost
Microsoft-Windows-Services-Svchost
Microsoft-Windows-PushNotifications-Developer
Microsoft-Windows-PushNotifications-Developer
Microsoft-Windows-LiveId
Microsoft-Windows-LiveId
Microsoft-Windows-Security-SPP-UX
Microsoft-Windows-Security-SPP-UX
Microsoft-Windows-VAN
Microsoft-Windows-VAN
Microsoft-Windows-FirstUX-PerfInstrumentation
Microsoft-Windows-FirstUX-PerfInstrumentation
Microsoft-Windows-Kernel-Tm
Microsoft-Windows-Kernel-Tm
Microsoft-Windows-Kernel-ShimEngine
Microsoft-Windows-Kernel-ShimEngine
Microsoft-Windows-EapHost
Microsoft-Windows-EapHost
Microsoft-Windows-CertPolEng
Microsoft-Windows-CertPolEng
Microsoft-Windows-MsLbfoEventProvider
Microsoft-Windows-MsLbfoEventProvider
Microsoft-Windows-Complus
Microsoft-Windows-Complus
Microsoft-Windows-EFS
Microsoft-Windows-EFS
Microsoft-Windows-WwaHost
Microsoft-Windows-WwaHost
Microsoft-Windows-ServerManager
Microsoft-Windows-ServerManager
Microsoft-Windows-ComDlg32
Microsoft-Windows-ComDlg32
Microsoft-Windows-MP4SDECD
Microsoft-Windows-MP4SDECD
Microsoft-Windows-PeopleNearMe
Microsoft-Windows-PeopleNearMe
Microsoft-Windows-SmartCard-Bluetooth-Profile
Microsoft-Windows-SmartCard-Bluetooth-Profile
Microsoft-Windows-TZUtil
Microsoft-Windows-TZUtil
Microsoft-Windows-ApplicationExperience-SwitchBack
Microsoft-Windows-ApplicationExperience-SwitchBack
Microsoft-Windows-UI-Input-Inking
Microsoft-Windows-UI-Input-Inking
Microsoft-Windows-VDRVROOT
Microsoft-Windows-VDRVROOT
Windows Firewall NetShell Plugin
Windows Firewall NetShell Plugin
Windows Firewall API
Windows Firewall API
Microsoft-Windows-Kernel-Acpi
Microsoft-Windows-Kernel-Acpi
Microsoft-Windows-WinRM
Microsoft-Windows-WinRM
Microsoft-Windows-Direct3D10_1
Microsoft-Windows-Direct3D10_1
Microsoft-Windows-Kernel-LicensingSqm
Microsoft-Windows-Kernel-LicensingSqm
Microsoft-Windows-SpoolerSpoolss
Microsoft-Windows-SpoolerSpoolss
Microsoft-Windows-FilterManager
Microsoft-Windows-FilterManager
Microsoft-Windows-ActionQueue
Microsoft-Windows-ActionQueue
Microsoft-Windows-IME-KRAPI
Microsoft-Windows-IME-KRAPI
Microsoft-Windows-Resource-Exhaustion-Detector
Microsoft-Windows-Resource-Exhaustion-Detector
Microsoft-Windows-ApplicationExperienceInfrastructure
Microsoft-Windows-ApplicationExperienceInfrastructure
Microsoft-Windows-StorSqm
Microsoft-Windows-StorSqm
Microsoft-Windows-Search
Microsoft-Windows-Search
Microsoft-Windows-HttpEvent
Microsoft-Windows-HttpEvent
Microsoft-Windows-AxInstallService
Microsoft-Windows-AxInstallService
Microsoft-Windows-Diagnosis-PerfHost
Microsoft-Windows-Diagnosis-PerfHost
Microsoft-Windows-International
Microsoft-Windows-International
Microsoft-Windows-CertificateServicesClient-CredentialRoaming
Microsoft-Windows-CertificateServicesClient-CredentialRoaming
Microsoft-Windows-SoftwareRestrictionPolicies
Microsoft-Windows-SoftwareRestrictionPolicies
Microsoft-Windows-Windows Defender
Microsoft-Windows-Windows Defender
Microsoft-Windows-ShareMedia-ControlPanel
Microsoft-Windows-ShareMedia-ControlPanel
Microsoft-Windows-CertificateServicesClient-Lifecycle-User
Microsoft-Windows-CertificateServicesClient-Lifecycle-User
Microsoft-Windows-WPD-MTPUS
Microsoft-Windows-WPD-MTPUS
Microsoft-Windows-DirectWrite
Microsoft-Windows-DirectWrite
Microsoft-Windows-RPCSS
Microsoft-Windows-RPCSS
Microsoft-Windows-DeviceSync
Microsoft-Windows-DeviceSync
Microsoft-Windows-NcdAutoSetup
Microsoft-Windows-NcdAutoSetup
Microsoft-Windows-Diagnosis-PCW
Microsoft-Windows-Diagnosis-PCW
Microsoft-Windows-DistributedCOM
Microsoft-Windows-DistributedCOM
ATA Port Driver Tracing Provider
ATA Port Driver Tracing Provider
Microsoft-Windows-WebdavClient-LookupServiceTrigger
Microsoft-Windows-WebdavClient-LookupServiceTrigger
Microsoft-Windows-USB-USBXHCI
Microsoft-Windows-USB-USBXHCI
Microsoft-Windows-Diagnosis-PLA
Microsoft-Windows-Diagnosis-PLA
Microsoft-Windows-WlanConn
Microsoft-Windows-WlanConn
Microsoft-Windows-Winlogon
Microsoft-Windows-Winlogon
Microsoft-Windows-stobject
Microsoft-Windows-stobject
Microsoft-Windows-Mobile-Broadband-Experience-SmsRouter
Microsoft-Windows-Mobile-Broadband-Experience-SmsRouter
Microsoft-Windows-D3D10Level9
Microsoft-Windows-D3D10Level9
Microsoft-Windows-WAS-ListenerAdapter
Microsoft-Windows-WAS-ListenerAdapter
Microsoft-Windows-ServerManager-MultiMachine
Microsoft-Windows-ServerManager-MultiMachine
Microsoft-Windows-AppxPackagingOM
Microsoft-Windows-AppxPackagingOM
Microsoft-Windows-PushNotifications-Platform
Microsoft-Windows-PushNotifications-Platform
Microsoft-Windows-OOBE-Machine-Plugins-Wireless
Microsoft-Windows-OOBE-Machine-Plugins-Wireless
Microsoft-Windows-IME-JPAPI
Microsoft-Windows-IME-JPAPI
SBP2 Port Driver Tracing Provider
SBP2 Port Driver Tracing Provider
Microsoft-Windows-BranchCacheEventProvider
Microsoft-Windows-BranchCacheEventProvider
Microsoft-Windows-Immersive-Shell-API
Microsoft-Windows-Immersive-Shell-API
Microsoft-Windows-ntshrui
Microsoft-Windows-ntshrui
Microsoft-Windows-KPSSVC
Microsoft-Windows-KPSSVC
Microsoft-Windows-BitLocker-DrivePreparationTool
Microsoft-Windows-BitLocker-DrivePreparationTool
Microsoft-Windows-EapMethods-Sim
Microsoft-Windows-EapMethods-Sim
Microsoft-Windows-Shell-ZipFolder
Microsoft-Windows-Shell-ZipFolder
Microsoft-Windows-Search-Core
Microsoft-Windows-Search-Core
Microsoft-Windows-OfflineFiles-CscNetApi
Microsoft-Windows-OfflineFiles-CscNetApi
Microsoft-Windows-Diagnosis-WDI
Microsoft-Windows-Diagnosis-WDI
Microsoft-Windows-PortableDeviceSyncProvider
Microsoft-Windows-PortableDeviceSyncProvider
Microsoft-Windows-Diagnostics-PerfTrack-Counters
Microsoft-Windows-Diagnostics-PerfTrack-Counters
Microsoft-Windows-Speech-TTS
Microsoft-Windows-Speech-TTS
Microsoft-Windows-Component-Resources-MrmCore-Events
Microsoft-Windows-Component-Resources-MrmCore-Events
Microsoft-Windows-BranchCache
Microsoft-Windows-BranchCache
Microsoft-Windows-SystemEventsBroker
Microsoft-Windows-SystemEventsBroker
Microsoft-Windows-VolumeControl
Microsoft-Windows-VolumeControl
Microsoft-Windows-Win32k
Microsoft-Windows-Win32k
Microsoft-Windows-Kernel-WHEA
Microsoft-Windows-Kernel-WHEA
Microsoft-Windows-P2P-Meetings
Microsoft-Windows-P2P-Meetings
Microsoft-Windows-Diagnosis-WDC
Microsoft-Windows-Diagnosis-WDC
Microsoft-Windows-Serial-ClassExtension
Microsoft-Windows-Serial-ClassExtension
Microsoft-Windows-KPSSVC-WPP
Microsoft-Windows-KPSSVC-WPP
Microsoft-Windows-CertificateServices-Deployment
Microsoft-Windows-CertificateServices-Deployment
Microsoft-Windows-PerfOS
Microsoft-Windows-PerfOS
Microsoft-Windows-ResetEng
Microsoft-Windows-ResetEng
Microsoft-Windows-Runtime-Graphics
Microsoft-Windows-Runtime-Graphics
Microsoft-Windows-IPSEC-SRV
Microsoft-Windows-IPSEC-SRV
Microsoft-Windows-CorruptedFileRecovery-Server
Microsoft-Windows-CorruptedFileRecovery-Server
Windows Mobile Bluetooth Connectivity
Windows Mobile Bluetooth Connectivity
Microsoft-Windows-DLNA-Namespace
Microsoft-Windows-DLNA-Namespace
Microsoft-Windows-WLAN-MediaManager
Microsoft-Windows-WLAN-MediaManager
Certificate Services Client Trace
Certificate Services Client Trace
Microsoft-Windows-BranchCacheSMB
Microsoft-Windows-BranchCacheSMB
Microsoft-Windows-PrintService-USBMon
Microsoft-Windows-PrintService-USBMon
Microsoft-Windows-OOBE-Machine
Microsoft-Windows-OOBE-Machine
Microsoft-Windows-DXP
Microsoft-Windows-DXP
Microsoft-Windows-Immersive-Shell
Microsoft-Windows-Immersive-Shell
Microsoft-Windows-OOBE-Machine-Plugins
Microsoft-Windows-OOBE-Machine-Plugins
Microsoft-Windows-Reliability-Analysis-Engine
Microsoft-Windows-Reliability-Analysis-Engine
Microsoft-Windows-Application-Experience
Microsoft-Windows-Application-Experience
Microsoft-Windows-KdsSvc
Microsoft-Windows-KdsSvc
Microsoft-Windows-MediaFoundation-Platform
Microsoft-Windows-MediaFoundation-Platform
Microsoft-Windows-Security-Configuration-Wizard
Microsoft-Windows-Security-Configuration-Wizard
Microsoft-Windows-DisplayColorCalibration
Microsoft-Windows-DisplayColorCalibration
Windows Mobile Device Center Base
Windows Mobile Device Center Base
Microsoft-Windows-WPD-MTPClassDriver
Microsoft-Windows-WPD-MTPClassDriver
Microsoft-Windows-DNS-Client
Microsoft-Windows-DNS-Client
Microsoft-Windows-MSDTC Client
Microsoft-Windows-MSDTC Client
Microsoft-Windows-NDIS-PacketCapture
Microsoft-Windows-NDIS-PacketCapture
Windows Remote Management Trace
Windows Remote Management Trace
Microsoft-Windows-MSPaint
Microsoft-Windows-MSPaint
Microsoft-Windows-HomeGroup-ListenerService
Microsoft-Windows-HomeGroup-ListenerService
Microsoft-Windows-Sensor-Service-Trigger
Microsoft-Windows-Sensor-Service-Trigger
Microsoft-Windows-EapMethods-Ttls
Microsoft-Windows-EapMethods-Ttls
Microsoft-Windows-Remotefs-Smb
Microsoft-Windows-Remotefs-Smb
Microsoft-Windows-SMBWitnessClient
Microsoft-Windows-SMBWitnessClient
Microsoft-Windows-USB-USBHUB
Microsoft-Windows-USB-USBHUB
Microsoft-Windows-DirectWrite-FontCache
Microsoft-Windows-DirectWrite-FontCache
Microsoft-Windows-WindowsBackup
Microsoft-Windows-WindowsBackup
Microsoft-Windows-NWiFi
Microsoft-Windows-NWiFi
Microsoft-Windows-WER-Diag
Microsoft-Windows-WER-Diag
Microsoft-Windows-UAC
Microsoft-Windows-UAC
Microsoft-Windows-LUA
Microsoft-Windows-LUA
Microsoft-Windows-AppID
Microsoft-Windows-AppID
Microsoft-Windows-IIS-WMSVC
Microsoft-Windows-IIS-WMSVC
Microsoft-Windows-Shell-OpenWith
Microsoft-Windows-Shell-OpenWith
Microsoft-Windows-MediaFoundation-MFReadWrite
Microsoft-Windows-MediaFoundation-MFReadWrite
Microsoft-Windows-BrokerInfrastructure
Microsoft-Windows-BrokerInfrastructure
Microsoft-Windows-Fault-Tolerant-Heap
Microsoft-Windows-Fault-Tolerant-Heap
Microsoft-Windows-Shell-DefaultPrograms
Microsoft-Windows-Shell-DefaultPrograms
Microsoft-Windows-Dism-Cli
Microsoft-Windows-Dism-Cli
Microsoft-Windows-SMBDirect
Microsoft-Windows-SMBDirect
Microsoft-Windows-IME-SCTIP
Microsoft-Windows-IME-SCTIP
Microsoft-Windows-EnergyEfficiencyWizard
Microsoft-Windows-EnergyEfficiencyWizard
Microsoft-Windows-ParentalControls
Microsoft-Windows-ParentalControls
Microsoft-Windows-Smartcard-Server
Microsoft-Windows-Smartcard-Server
Microsoft-Windows-FMS
Microsoft-Windows-FMS
Microsoft-Windows-Devices-Location
Microsoft-Windows-Devices-Location
Microsoft-Windows-LLTD-Responder
Microsoft-Windows-LLTD-Responder
Microsoft-Windows-MsLbfoSysEvtProvider
Microsoft-Windows-MsLbfoSysEvtProvider
sqlos
sqlos
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Microsoft-Windows-SCPNP
Microsoft-Windows-SCPNP
Microsoft-Windows-Wordpad
Microsoft-Windows-Wordpad
WMI_Tracing_Client_Operations
WMI_Tracing_Client_Operations
Microsoft-Windows-Security-Audit-Configuration-Client
Microsoft-Windows-Security-Audit-Configuration-Client
Microsoft-Windows-EFSADU
Microsoft-Windows-EFSADU
Windows Notification Facility Provider
Windows Notification Facility Provider
Microsoft-Windows-DiagCpl
Microsoft-Windows-DiagCpl
Windows NetworkItemFactory Trace
Windows NetworkItemFactory Trace
Microsoft-Windows-ApplicationExperience-Cache
Microsoft-Windows-ApplicationExperience-Cache
Microsoft-Windows-ResourcePublication
Microsoft-Windows-ResourcePublication
Microsoft-Windows-FailoverClustering-Client
Microsoft-Windows-FailoverClustering-Client
Microsoft-Windows-Runtime-Networking-BackgroundTransfer
Microsoft-Windows-Runtime-Networking-BackgroundTransfer
Microsoft-Windows-AppHost
Microsoft-Windows-AppHost
Microsoft-Windows-NetAdapterCim-Diag
Microsoft-Windows-NetAdapterCim-Diag
Microsoft-Windows-IIS-FTP
Microsoft-Windows-IIS-FTP
Microsoft-Windows-Iphlpsvc
Microsoft-Windows-Iphlpsvc
Microsoft-Windows-WinINet
Microsoft-Windows-WinINet
Microsoft-Windows-TabletPC-InputPersonalization
Microsoft-Windows-TabletPC-InputPersonalization
Microsoft-Windows-SpoolerFilterPipelineSVC
Microsoft-Windows-SpoolerFilterPipelineSVC
Microsoft-Windows-Globalization
Microsoft-Windows-Globalization
Microsoft-Windows-Bits-Client
Microsoft-Windows-Bits-Client
Microsoft-Windows-WFP
Microsoft-Windows-WFP
Microsoft-Windows-Services
Microsoft-Windows-Services
Microsoft-Windows-IdleTriggerProvider
Microsoft-Windows-IdleTriggerProvider
Microsoft-Windows-DxgKrnl
Microsoft-Windows-DxgKrnl
Microsoft-Windows-HealthCenter
Microsoft-Windows-HealthCenter
Microsoft-Windows-OtpCredentialProviderEvt
Microsoft-Windows-OtpCredentialProviderEvt
Microsoft-Windows-MemoryDiagnostics-Results
Microsoft-Windows-MemoryDiagnostics-Results
Microsoft-Windows-Ncasvc
Microsoft-Windows-Ncasvc
Microsoft-Windows-SystemSettings
Microsoft-Windows-SystemSettings
Microsoft-Windows-PDH
Microsoft-Windows-PDH
Microsoft-Windows-WMPNSSUI
Microsoft-Windows-WMPNSSUI
Microsoft-Windows-BdeTriggerProvider
Microsoft-Windows-BdeTriggerProvider
Microsoft-Windows-Diagnostics-PerfTrack
Microsoft-Windows-Diagnostics-PerfTrack
Microsoft-Windows-IIS-APPHOSTSVC
Microsoft-Windows-IIS-APPHOSTSVC
Microsoft-Windows-CoreWindow
Microsoft-Windows-CoreWindow
Microsoft-Windows-Help
Microsoft-Windows-Help
Microsoft-Windows-WindowsUpdateClient
Microsoft-Windows-WindowsUpdateClient
Microsoft-Windows-IIS-W3SVC-PerfCounters
Microsoft-Windows-IIS-W3SVC-PerfCounters
Microsoft-Windows-WMI
Microsoft-Windows-WMI
Microsoft-Windows-TabletPC-Platform-Input-Wisp
Microsoft-Windows-TabletPC-Platform-Input-Wisp
Microsoft-Windows-ProcessExitMonitor
Microsoft-Windows-ProcessExitMonitor
Microsoft-Windows-IME-JPSetting
Microsoft-Windows-IME-JPSetting
Microsoft-Windows-Diagnosis-Scripted
Microsoft-Windows-Diagnosis-Scripted
Microsoft-Windows-GroupPolicyTriggerProvider
Microsoft-Windows-GroupPolicyTriggerProvider
File Kernel Trace; Operation Set 2
File Kernel Trace; Operation Set 2
Microsoft-Windows-IIS-Configuration
Microsoft-Windows-IIS-Configuration
Microsoft-Windows-Diagnosis-TaskManager
Microsoft-Windows-Diagnosis-TaskManager
Microsoft-Windows-Diagnosis-DPS
Microsoft-Windows-Diagnosis-DPS
Microsoft-Windows-UserPnp
Microsoft-Windows-UserPnp
Microsoft-Windows-Security-SPP-UX-GenuineCenter-Logging
Microsoft-Windows-Security-SPP-UX-GenuineCenter-Logging
Microsoft-Windows-Schannel-Events
Microsoft-Windows-Schannel-Events
NetJoin
NetJoin
Microsoft-Windows-TabletPC-InputPanel
Microsoft-Windows-TabletPC-InputPanel
Microsoft-Windows-FileServices-ServerManager-EventProvider
Microsoft-Windows-FileServices-ServerManager-EventProvider
Microsoft-Windows-MediaFoundation-Performance
Microsoft-Windows-MediaFoundation-Performance
Microsoft-Windows-EndpointTriggerProvider
Microsoft-Windows-EndpointTriggerProvider
Microsoft-Windows-IME-KRTIP
Microsoft-Windows-IME-KRTIP
Microsoft-Windows-Mobile-Broadband-Experience-SmsApi
Microsoft-Windows-Mobile-Broadband-Experience-SmsApi
Microsoft-Windows-Hyper-V-Netvsc
Microsoft-Windows-Hyper-V-Netvsc
Microsoft-Windows-DirectSound
Microsoft-Windows-DirectSound
Microsoft-Windows-TabletPC-Platform-Input-Core
Microsoft-Windows-TabletPC-Platform-Input-Core
Microsoft-Windows-PushNotifications-InProc
Microsoft-Windows-PushNotifications-InProc
Microsoft-Windows-Kernel-Network
Microsoft-Windows-Kernel-Network
Microsoft-Windows-DiskDiagnosticResolver
Microsoft-Windows-DiskDiagnosticResolver
Microsoft-Windows-NdisImPlatformSysEvtProvider
Microsoft-Windows-NdisImPlatformSysEvtProvider
Microsoft-Windows-MeetingSpace
Microsoft-Windows-MeetingSpace
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Microsoft-Windows-RasServer
Microsoft-Windows-RasServer
Microsoft-Windows-VHDMP
Microsoft-Windows-VHDMP
Microsoft-Windows-WindowsSystemAssessmentTool
Microsoft-Windows-WindowsSystemAssessmentTool
Microsoft-Windows-DCLocator
Microsoft-Windows-DCLocator
Microsoft-Windows-Diagnosis-MSDT
Microsoft-Windows-Diagnosis-MSDT
Microsoft-Windows-WLGPA
Microsoft-Windows-WLGPA
SQLSRV32.1
SQLSRV32.1
Microsoft-Windows-CertificateServicesClient-CertEnroll
Microsoft-Windows-CertificateServicesClient-CertEnroll
Microsoft-Windows-IME-TCCORE
Microsoft-Windows-IME-TCCORE
Microsoft-Windows-SmartCard-Bluetooth-Transport
Microsoft-Windows-SmartCard-Bluetooth-Transport
Microsoft-Windows-WMVENCOD
Microsoft-Windows-WMVENCOD
Microsoft-Windows-mobsync
Microsoft-Windows-mobsync
Microsoft-Windows-EFSTriggerProvider
Microsoft-Windows-EFSTriggerProvider
Microsoft-Windows-DUSER
Microsoft-Windows-DUSER
Microsoft-Windows-DiskDiagnosticDataCollector
Microsoft-Windows-DiskDiagnosticDataCollector
Microsoft-Windows-DirectAccess-MediaManager
Microsoft-Windows-DirectAccess-MediaManager
Microsoft-Windows-DisplaySwitch
Microsoft-Windows-DisplaySwitch
Microsoft-Windows-PackageStateRoaming
Microsoft-Windows-PackageStateRoaming
Microsoft-Windows-Crypto-DPAPI
Microsoft-Windows-Crypto-DPAPI
Microsoft-Windows-IME-CustomerFeedbackManagerUI
Microsoft-Windows-IME-CustomerFeedbackManagerUI
sqlserver
sqlserver
Microsoft-Windows-User-Loader
Microsoft-Windows-User-Loader
Microsoft-Windows-NetworkProfileTriggerProvider
Microsoft-Windows-NetworkProfileTriggerProvider
Microsoft-Windows-NetworkProfile
Microsoft-Windows-NetworkProfile
Windows Firewall API - GP
Windows Firewall API - GP
Microsoft-Windows-CmiSetup
Microsoft-Windows-CmiSetup
Microsoft-Windows-Sysprep
Microsoft-Windows-Sysprep
Microsoft-Windows-Windeploy
Microsoft-Windows-Windeploy
Microsoft-Windows-Setup
Microsoft-Windows-Setup
Microsoft-Windows-OobeLdr
Microsoft-Windows-OobeLdr
Microsoft-Windows-SetupUGC
Microsoft-Windows-SetupUGC
Microsoft-Windows-Audit
Microsoft-Windows-Audit
Microsoft-Windows-SetupCl
Microsoft-Windows-SetupCl
Microsoft-Windows-Winsrv
Microsoft-Windows-Winsrv
Microsoft-Windows-WinHttp
Microsoft-Windows-WinHttp
Microsoft-Windows-RadioManager
Microsoft-Windows-RadioManager
Microsoft-Windows-Websocket-Protocol-Component
Microsoft-Windows-Websocket-Protocol-Component
Microsoft-Windows-WebIO
Microsoft-Windows-WebIO
Microsoft-Windows-Dwm-Core
Microsoft-Windows-Dwm-Core
Microsoft-Windows-Registry-SQM-Provider
Microsoft-Windows-Registry-SQM-Provider
Microsoft-Windows-WHEA-Logger
Microsoft-Windows-WHEA-Logger
Microsoft-Windows-PeerToPeerDrtEventProvider
Microsoft-Windows-PeerToPeerDrtEventProvider
Microsoft-Windows-BitLocker-Driver
Microsoft-Windows-BitLocker-Driver
Microsoft-Windows-SettingSync
Microsoft-Windows-SettingSync
Microsoft-Windows-Mobile-Broadband-Experience-Api-Internal
Microsoft-Windows-Mobile-Broadband-Experience-Api-Internal
Microsoft-Windows-EnhancedStorage-EhStorTcgDrv
Microsoft-Windows-EnhancedStorage-EhStorTcgDrv
Microsoft-Windows-PowerShell
Microsoft-Windows-PowerShell
Microsoft-Windows-DirectShow-Core
Microsoft-Windows-DirectShow-Core
Microsoft-Windows-Kernel-Power
Microsoft-Windows-Kernel-Power
Microsoft-Windows-msmpeg2venc
Microsoft-Windows-msmpeg2venc
Microsoft-Windows-MPEG2_DLNA-Encoder
Microsoft-Windows-MPEG2_DLNA-Encoder
Microsoft-Windows-Remote-FileSystem-Log
Microsoft-Windows-Remote-FileSystem-Log
Microsoft-Windows-Kernel-PnP
Microsoft-Windows-Kernel-PnP
Microsoft-Windows-AppXDeployment-Server
Microsoft-Windows-AppXDeployment-Server
Microsoft-Windows-Folder Redirection
Microsoft-Windows-Folder Redirection
Microsoft-Windows-OfflineFiles-CscUM
Microsoft-Windows-OfflineFiles-CscUM
Microsoft-Windows-ServerManager-DeploymentProvider
Microsoft-Windows-ServerManager-DeploymentProvider
Microsoft-Windows-ServiceReportingApi
Microsoft-Windows-ServiceReportingApi
Microsoft-Windows-StorDiag
Microsoft-Windows-StorDiag
Microsoft-Windows-IME-CustomerFeedbackManager
Microsoft-Windows-IME-CustomerFeedbackManager
Microsoft-Windows-Kernel-EventTracing
Microsoft-Windows-Kernel-EventTracing
Microsoft-Windows-Kernel-BootDiagnostics
Microsoft-Windows-Kernel-BootDiagnostics
Microsoft-Windows-DXGI
Microsoft-Windows-DXGI
Microsoft-Windows-Build-RegDll
Microsoft-Windows-Build-RegDll
Microsoft-Windows-PNRPSvc
Microsoft-Windows-PNRPSvc
Microsoft-Windows-Ndu
Microsoft-Windows-Ndu
Microsoft-Windows-Firewall
Microsoft-Windows-Firewall
Microsoft-Windows-Wcmsvc
Microsoft-Windows-Wcmsvc
Microsoft-Windows-OLEACC
Microsoft-Windows-OLEACC
Microsoft-Windows-MSDTC Client 2
Microsoft-Windows-MSDTC Client 2
Microsoft-Windows-InputSwitch
Microsoft-Windows-InputSwitch
Microsoft-Windows-Runtime-WebAPI
Microsoft-Windows-Runtime-WebAPI
Microsoft-Windows-HAL
Microsoft-Windows-HAL
Microsoft-Windows-International-RegionalOptionsControlPanel
Microsoft-Windows-International-RegionalOptionsControlPanel
Microsoft-Windows-RPC
Microsoft-Windows-RPC
Microsoft-Windows-MFH264Enc
Microsoft-Windows-MFH264Enc
Microsoft-Windows-SharedAccess_NAT
Microsoft-Windows-SharedAccess_NAT
Microsoft-Windows-DeviceAssociationService
Microsoft-Windows-DeviceAssociationService
Microsoft-Windows-Bluetooth-MTPEnum
Microsoft-Windows-Bluetooth-MTPEnum
Microsoft-Windows-BitLocker-API
Microsoft-Windows-BitLocker-API
{C5BFFE2E-9D87-D568-A09E-08FC83D0C7C2}
{C5BFFE2E-9D87-D568-A09E-08FC83D0C7C2}
Microsoft-Windows-IPMIProvider
Microsoft-Windows-IPMIProvider
Microsoft-Windows-IME-TIP
Microsoft-Windows-IME-TIP
Microsoft-Windows-WindowsToGo-StartupOptions
Microsoft-Windows-WindowsToGo-StartupOptions
Microsoft-Windows-Backup
Microsoft-Windows-Backup
Microsoft-Windows-WMP-MediaDeliveryEngine
Microsoft-Windows-WMP-MediaDeliveryEngine
Microsoft-Windows-PrintBRM
Microsoft-Windows-PrintBRM
Microsoft-Windows-ServerManager-ConfigureSMRemoting
Microsoft-Windows-ServerManager-ConfigureSMRemoting
Microsoft-Windows-Video-For-Windows
Microsoft-Windows-Video-For-Windows
Microsoft-Windows-ClearTypeTextTuner
Microsoft-Windows-ClearTypeTextTuner
Microsoft-Windows-Subsys-Csr
Microsoft-Windows-Subsys-Csr
Microsoft-Windows-USB-UCX
Microsoft-Windows-USB-UCX
Microsoft-Windows-RemoteApp and Desktop Connections
Microsoft-Windows-RemoteApp and Desktop Connections
Windows Winlogon Trace
Windows Winlogon Trace
Microsoft-Windows-RasSstp
Microsoft-Windows-RasSstp
Microsoft-Windows-UAC-FileVirtualization
Microsoft-Windows-UAC-FileVirtualization
Microsoft-Windows-ClassicSruMon
Microsoft-Windows-ClassicSruMon
Microsoft-Windows-Security-IdentityListener
Microsoft-Windows-Security-IdentityListener
Microsoft-Windows-WWAN-MM-EVENTS
Microsoft-Windows-WWAN-MM-EVENTS
Microsoft-Windows-MsiServer
Microsoft-Windows-MsiServer
Microsoft-Windows-PhotoAcq
Microsoft-Windows-PhotoAcq
Microsoft-Windows-Power-Troubleshooter
Microsoft-Windows-Power-Troubleshooter
Microsoft-Windows-DxpTaskSyncProvider
Microsoft-Windows-DxpTaskSyncProvider
Microsoft-Windows-Remotefs-Rdbss
Microsoft-Windows-Remotefs-Rdbss
Microsoft-Windows-AppIDServiceTrigger
Microsoft-Windows-AppIDServiceTrigger
Microsoft-Windows-Kernel-File
Microsoft-Windows-Kernel-File
Microsoft-Windows-TSF-msctf
Microsoft-Windows-TSF-msctf
Microsoft-Windows-PowerCpl
Microsoft-Windows-PowerCpl
Microsoft-Windows-LanGPA
Microsoft-Windows-LanGPA
Microsoft-Windows-WWAN-MediaManager
Microsoft-Windows-WWAN-MediaManager
Microsoft-Windows-PrimaryNetworkIcon
Microsoft-Windows-PrimaryNetworkIcon
Microsoft-Windows-OfflineFiles
Microsoft-Windows-OfflineFiles
Microsoft-Windows-UIAnimation
Microsoft-Windows-UIAnimation
Microsoft-Windows-Security-Auditing
Microsoft-Windows-Security-Auditing
Microsoft-Windows-WCN-Config-Registrar-Wizard-Trace
Microsoft-Windows-WCN-Config-Registrar-Wizard-Trace
Microsoft-Windows-WWAN-NDISUIO-EVENTS
Microsoft-Windows-WWAN-NDISUIO-EVENTS
Microsoft-Windows-NetworkManagerTriggerProvider
Microsoft-Windows-NetworkManagerTriggerProvider
Microsoft-Windows-Winsock-AFD
Microsoft-Windows-Winsock-AFD
Microsoft-Windows-Remote-FileSystem-Monitor
Microsoft-Windows-Remote-FileSystem-Monitor
Microsoft-Windows-WABSyncProvider
Microsoft-Windows-WABSyncProvider
.NET Common Language Runtime
.NET Common Language Runtime
Microsoft-Windows-MSMPEG2VDEC
Microsoft-Windows-MSMPEG2VDEC
Microsoft-Windows-DateTimeControlPanel
Microsoft-Windows-DateTimeControlPanel
Windows Firewall Driver
Windows Firewall Driver
Microsoft-Windows-IIS-W3SVC
Microsoft-Windows-IIS-W3SVC
Microsoft-Windows-WWAN-UI-EVENTS
Microsoft-Windows-WWAN-UI-EVENTS
Microsoft-Windows-Speech-UserExperience
Microsoft-Windows-Speech-UserExperience
Microsoft-Windows-Dism-Api
Microsoft-Windows-Dism-Api
Microsoft-Windows-Store-Client-UI
Microsoft-Windows-Store-Client-UI
Microsoft-Windows-Calculator
Microsoft-Windows-Calculator
Microsoft-Windows-Shell-ConnectedAccountState
Microsoft-Windows-Shell-ConnectedAccountState
Microsoft-Windows-PrintDialogs
Microsoft-Windows-PrintDialogs
Microsoft-Windows-Network-and-Sharing-Center
Microsoft-Windows-Network-and-Sharing-Center
Microsoft-Windows-Crypto-RNG
Microsoft-Windows-Crypto-RNG
Microsoft-Windows-MSDTC 2
Microsoft-Windows-MSDTC 2
Microsoft-Windows-SpellChecker
Microsoft-Windows-SpellChecker
Microsoft-Windows-propsys
Microsoft-Windows-propsys
Microsoft-Windows-WPD-MTPIP
Microsoft-Windows-WPD-MTPIP
Microsoft-Windows-Documents
Microsoft-Windows-Documents
Microsoft-Windows-StorPort
Microsoft-Windows-StorPort
Microsoft-Windows-Magnification
Microsoft-Windows-Magnification
Microsoft-Windows-Shell-AuthUI
Microsoft-Windows-Shell-AuthUI
Microsoft-Windows-Dwm-Redir
Microsoft-Windows-Dwm-Redir
Microsoft-Windows-BTH-BTHUSB
Microsoft-Windows-BTH-BTHUSB
Microsoft-Windows-Ntfs
Microsoft-Windows-Ntfs
Microsoft-Windows-Sens
Microsoft-Windows-Sens
Microsoft-Windows-UserAccessLogging
Microsoft-Windows-UserAccessLogging
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Microsoft-Windows-COM-Perf
Microsoft-Windows-COM-Perf
Microsoft-Windows-StorageSpaces-BackgroundAgent
Microsoft-Windows-StorageSpaces-BackgroundAgent
Microsoft-Windows-Kernel-Prefetch
Microsoft-Windows-Kernel-Prefetch
Portable Device Connectivity API Trace
Portable Device Connectivity API Trace
Microsoft-Windows-RemoteAssistance
Microsoft-Windows-RemoteAssistance
Microsoft-Windows-MF
Microsoft-Windows-MF
Microsoft-Windows-MediaFoundation-MSVProc
Microsoft-Windows-MediaFoundation-MSVProc
Microsoft-Windows-TBS
Microsoft-Windows-TBS
Microsoft-Windows-FeedbackTool
Microsoft-Windows-FeedbackTool
Microsoft-Windows-WlanPref
Microsoft-Windows-WlanPref
Microsoft-Windows-OfflineFiles-CscDclUser
Microsoft-Windows-OfflineFiles-CscDclUser
Microsoft-Windows-Http-SQM-Provider
Microsoft-Windows-Http-SQM-Provider
Microsoft-Windows-Wireless-Network-Setup-Wizard-Trace
Microsoft-Windows-Wireless-Network-Setup-Wizard-Trace
Microsoft-Windows-MCT
Microsoft-Windows-MCT
Microsoft-Windows-HotStart
Microsoft-Windows-HotStart
Microsoft-Windows-Diagnostics-Networking
Microsoft-Windows-Diagnostics-Networking
Microsoft-Windows-Sensors
Microsoft-Windows-Sensors
Microsoft-Windows-SmbServer
Microsoft-Windows-SmbServer
Microsoft-Windows-USB-USBHUB3
Microsoft-Windows-USB-USBHUB3
Microsoft-Windows-Dot3MM
Microsoft-Windows-Dot3MM
Microsoft-Windows-KernelStreaming
Microsoft-Windows-KernelStreaming
Microsoft-Windows-Mobile-Broadband-Experience-Api
Microsoft-Windows-Mobile-Broadband-Experience-Api
Microsoft-Windows-VolumeSnapshot-Driver
Microsoft-Windows-VolumeSnapshot-Driver
Microsoft-Windows-MobilityCenter
Microsoft-Windows-MobilityCenter
Microsoft-Windows-OfflineFiles-CscService
Microsoft-Windows-OfflineFiles-CscService
Microsoft-Windows-Superfetch
Microsoft-Windows-Superfetch
Microsoft-Windows-IPBusEnum
Microsoft-Windows-IPBusEnum
Microsoft-Windows-Mprddm
Microsoft-Windows-Mprddm
Microsoft-Windows-Dwm-Udwm
Microsoft-Windows-Dwm-Udwm
Microsoft-Windows-AppModel-State
Microsoft-Windows-AppModel-State
Microsoft-Windows-WCN-FD-Provider-Trace
Microsoft-Windows-WCN-FD-Provider-Trace
Microsoft-Windows-Resource-Exhaustion-Resolver
Microsoft-Windows-Resource-Exhaustion-Resolver
Microsoft-Windows-Iphlpsvc-Trace
Microsoft-Windows-Iphlpsvc-Trace
Microsoft-Windows-WUSA
Microsoft-Windows-WUSA
Microsoft-Windows-TerminalServices-LocalSessionManager
Microsoft-Windows-TerminalServices-LocalSessionManager
Microsoft-Windows-RPC-FirewallManager
Microsoft-Windows-RPC-FirewallManager
Microsoft-Windows-WCN-Common-Trace
Microsoft-Windows-WCN-Common-Trace
Microsoft-Windows-MediaFoundation-MFCaptureEngine
Microsoft-Windows-MediaFoundation-MFCaptureEngine
Microsoft-Windows-ReadyBoostDriver
Microsoft-Windows-ReadyBoostDriver
Microsoft-Windows-DUI
Microsoft-Windows-DUI
Microsoft-Windows-WMP-Setup_WM
Microsoft-Windows-WMP-Setup_WM
Microsoft-Windows-Direct3D10
Microsoft-Windows-Direct3D10
Microsoft-Windows-DfsSvc
Microsoft-Windows-DfsSvc
Microsoft-Windows-IME-SCCORE
Microsoft-Windows-IME-SCCORE
Microsoft-Windows-NTLM
Microsoft-Windows-NTLM
Microsoft-Windows-VWiFi
Microsoft-Windows-VWiFi
Microsoft-Windows-Kernel-PnPConfig
Microsoft-Windows-Kernel-PnPConfig
Microsoft-Windows-Winsock-SQM
Microsoft-Windows-Winsock-SQM
Microsoft-Windows-SpoolerSpoolSV
Microsoft-Windows-SpoolerSpoolSV
Microsoft-Windows-Netshell
Microsoft-Windows-Netshell
Microsoft-Windows-UserModePowerService
Microsoft-Windows-UserModePowerService
Microsoft-Windows-HttpService
Microsoft-Windows-HttpService
HTTP Service Trace
HTTP Service Trace
Microsoft-Windows-D3D9
Microsoft-Windows-D3D9
Microsoft-Windows-AppModel-Runtime
Microsoft-Windows-AppModel-Runtime
Microsoft-Windows-CEIP
Microsoft-Windows-CEIP
Microsoft-Windows-Directory-Services-SAM
Microsoft-Windows-Directory-Services-SAM
Microsoft-Windows-SpoolerTCPMon
Microsoft-Windows-SpoolerTCPMon
Microsoft-Windows-ReadyBoost
Microsoft-Windows-ReadyBoost
Microsoft-Windows-L2NACP
Microsoft-Windows-L2NACP
Microsoft-Windows-LLTD-Mapper
Microsoft-Windows-LLTD-Mapper
Microsoft-Windows-Deduplication
Microsoft-Windows-Deduplication
Microsoft-Windows-HomeGroup-ControlPanel
Microsoft-Windows-HomeGroup-ControlPanel
Microsoft-Windows-Mobile-Broadband-Experience-Parser-Task
Microsoft-Windows-Mobile-Broadband-Experience-Parser-Task
Microsoft-Windows-DomainJoinManagerTriggerProvider
Microsoft-Windows-DomainJoinManagerTriggerProvider
Microsoft-Windows-SruMon
Microsoft-Windows-SruMon
Microsoft-Windows-ELS-Hyphenation
Microsoft-Windows-ELS-Hyphenation
TCPIP Service Trace
TCPIP Service Trace
Microsoft-Windows-DriverFrameworks-KernelMode
Microsoft-Windows-DriverFrameworks-KernelMode
Microsoft-Windows-CorruptedFileRecovery-Client
Microsoft-Windows-CorruptedFileRecovery-Client
Microsoft-Windows-WMI-Activity
Microsoft-Windows-WMI-Activity
Microsoft-Windows-COMRuntime
Microsoft-Windows-COMRuntime
Microsoft-Windows-WAS
Microsoft-Windows-WAS
Microsoft-Windows-Wnv
Microsoft-Windows-Wnv
Microsoft-Windows-Shsvcs
Microsoft-Windows-Shsvcs
Microsoft-Windows-NDIS
Microsoft-Windows-NDIS
Microsoft-Windows-WinMDE
Microsoft-Windows-WinMDE
File Kernel Trace; Operation Set 1
File Kernel Trace; Operation Set 1
Microsoft-Windows-Proximity-Common
Microsoft-Windows-Proximity-Common
Microsoft-Windows-Ntfs-UBPM
Microsoft-Windows-Ntfs-UBPM
Microsoft-Windows-Kernel-Registry
Microsoft-Windows-Kernel-Registry
Microsoft-Windows-RemoteDesktopServices-RemoteDesktopSessionManager
Microsoft-Windows-RemoteDesktopServices-RemoteDesktopSessionManager
Microsoft-Windows-TunnelDriver
Microsoft-Windows-TunnelDriver
Microsoft-Windows-QoS-Pacer
Microsoft-Windows-QoS-Pacer
Microsoft-Windows-EventCollector
Microsoft-Windows-EventCollector
Microsoft-Windows-OOBE-Machine-DUI
Microsoft-Windows-OOBE-Machine-DUI
Microsoft-Windows-IME-TCTIP
Microsoft-Windows-IME-TCTIP
Microsoft-Windows-WCNWiz
Microsoft-Windows-WCNWiz
Microsoft-Windows-Display
Microsoft-Windows-Display
Microsoft-Windows-OcSetup
Microsoft-Windows-OcSetup
Microsoft-Windows-DesktopWindowManager-Diag
Microsoft-Windows-DesktopWindowManager-Diag
Microsoft-Windows-FileInfoMinifilter
Microsoft-Windows-FileInfoMinifilter
Microsoft-Windows-TextPredictionEngine
Microsoft-Windows-TextPredictionEngine
Microsoft-Windows-NetworkGCW
Microsoft-Windows-NetworkGCW
Microsoft-Windows-DHCPv6-Client
Microsoft-Windows-DHCPv6-Client
Microsoft-Windows-PlayToManager
Microsoft-Windows-PlayToManager
NDIS_STATUS_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIG
NDIS_STATUS_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIG
NDIS_STATUS_PORT_STATE
NDIS_STATUS_PORT_STATE
MS_Windows_AeLookupServiceTrigger_Provider
MS_Windows_AeLookupServiceTrigger_Provider
Microsoft_Windows_SQM_Provider
Microsoft_Windows_SQM_Provider
MS_Windows_AIT_Provider
MS_Windows_AIT_Provider
NDIS_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIG
NDIS_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIG
NDIS_TCP_OFFLOAD_CURRENT_CONFIG
NDIS_TCP_OFFLOAD_CURRENT_CONFIG
PARPORT_WMI_ALLOCATE_FREE_COUNTS_GUID
PARPORT_WMI_ALLOCATE_FREE_COUNTS_GUID
NDIS_GEN_ENUMERATE_PORTS
NDIS_GEN_ENUMERATE_PORTS
GUID_QOS_TC_SUPPORTED
GUID_QOS_TC_SUPPORTED
MS1394_PortVendorRegisterAccessGuid
MS1394_PortVendorRegisterAccessGuid
iSCSI_PersistentLoginsGuid
iSCSI_PersistentLoginsGuid
iSCSI_PortalInfoClassGuid
iSCSI_PortalInfoClassGuid
SerailPortPerfGuid
SerailPortPerfGuid
PortClsEvent
PortClsEvent
UdpIpGuid
UdpIpGuid
TcpIpGuid
TcpIpGuid
iSCSI_OperationsGuid
iSCSI_OperationsGuid
CTLGUID_usbport
CTLGUID_usbport
NDIS_STATUS_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIES
NDIS_STATUS_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIES
iSCSI_DiscoveryOperationsGuid
iSCSI_DiscoveryOperationsGuid
SerialPortNameGuid
SerialPortNameGuid
CTLGUID_WebClntTrace
CTLGUID_WebClntTrace
POINTER_PORT_WMI_STD_DATA_GUID
POINTER_PORT_WMI_STD_DATA_GUID
KEYBOARD_PORT_WMI_STD_DATA_GUID
KEYBOARD_PORT_WMI_STD_DATA_GUID
MSKeyboard_ClassInformationGuid
MSKeyboard_ClassInformationGuid
NDIS_GEN_CO_MEDIA_SUPPORTED
NDIS_GEN_CO_MEDIA_SUPPORTED
MS_Windows_AeSwitchBack_Provider
MS_Windows_AeSwitchBack_Provider
SerialPortHWGuid
SerialPortHWGuid
MS_SM_PortInformationMethods
MS_SM_PortInformationMethods
ataport_CtlGuid
ataport_CtlGuid
storport_CtlGuid
storport_CtlGuid
MS1394_PortDriverInformationGuid
MS1394_PortDriverInformationGuid
BTHPORT_WMI_HCI_PACKET_INFO
BTHPORT_WMI_HCI_PACKET_INFO
SerialPortCommGuid
SerialPortCommGuid
iScsiLBOperationsGuid
iScsiLBOperationsGuid
MS_Windows_AeCache_Provider
MS_Windows_AeCache_Provider
NDIS_GEN_PORT_STATE
NDIS_GEN_PORT_STATE
WindowsBackup TracingControlGuid
WindowsBackup TracingControlGuid
WmiMonitorListedSupportedSourceModes_GUID
WmiMonitorListedSupportedSourceModes_GUID
NDIS_GEN_MEDIA_SUPPORTED
NDIS_GEN_MEDIA_SUPPORTED
CTLGUID_certprop
CTLGUID_certprop
BTHPORT_WMI_SDP_SERVER_LOG_INFO
BTHPORT_WMI_SDP_SERVER_LOG_INFO
KEYBOARD_PORT_WMI_EXTENDED_ID
KEYBOARD_PORT_WMI_EXTENDED_ID
iSCSIRedirectPortalGuid
iSCSIRedirectPortalGuid
NDIS_GEN_PORT_AUTHENTICATION_PARAMETERS
NDIS_GEN_PORT_AUTHENTICATION_PARAMETERS
BTHPORT_WMI_SDP_DATABASE_EVENT
BTHPORT_WMI_SDP_DATABASE_EVENT
NDIS_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIES
NDIS_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIES
iSCSI_TCPIPConfigGuid
iSCSI_TCPIPConfigGuid
SerialPortPropertiesGuid
SerialPortPropertiesGuid
PortCls_IrpProcessing
PortCls_IrpProcessing
iSCSI_SecurityConfigOperationsGuid
iSCSI_SecurityConfigOperationsGuid
NDIS_TCP_OFFLOAD_PARAMETERS
NDIS_TCP_OFFLOAD_PARAMETERS
PortCls_PowerState
PortCls_PowerState
Microsoft_Windows_GameUx
Microsoft_Windows_GameUx
iSCSI_InitiatorLoginStatisticsGuid
iSCSI_InitiatorLoginStatisticsGuid
MS1394_PortErrorInformationGuid
MS1394_PortErrorInformationGuid
PortCls_PinState
PortCls_PinState
CTLGUID_PortCls
CTLGUID_PortCls
NDIS_TCP_OFFLOAD_HARDWARE_CAPABILITIES
NDIS_TCP_OFFLOAD_HARDWARE_CAPABILITIES
CTRLGUID_MF_PIPELINE
CTRLGUID_MF_PIPELINE
.PX`i`
.PX`i`
`.HBS
`.HBS
&{%UD(_
&{%UD(_
dump_wmi_guidentries failed, error %d, status %X
dump_wmi_guidentries failed, error %d, status %X
dump_wmi_guidentries failed, error %d
dump_wmi_guidentries failed, error %d
dump_wmi_guidentries: cannot alloc %X bytes (total %d)
dump_wmi_guidentries: cannot alloc %X bytes (total %d)
dump_wmi_guidentries: read failed, error %d, status %X
dump_wmi_guidentries: read failed, error %d, status %X
dump_wmi_guidentries: read failed, error %d
dump_wmi_guidentries: read failed, error %d
WMI guidentries: total %X readed %X:
WMI guidentries: total %X readed %X:
[%X] %X flag %X refcnt %X - %s
[%X] %X flag %X refcnt %X - %s
[%X] %X flag %X refcnt %X %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
[%X] %X flag %X refcnt %X %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
dump_wmi_regentries failed, error %d, status %X
dump_wmi_regentries failed, error %d, status %X
dump_wmi_regentries failed, error %d
dump_wmi_regentries failed, error %d
dump_wmi_regentries: cannot alloc %X bytes (total %d)
dump_wmi_regentries: cannot alloc %X bytes (total %d)
dump_wmi_regentries: read failed, error %d, status %X
dump_wmi_regentries: read failed, error %d, status %X
dump_wmi_regentries: read failed, error %d
dump_wmi_regentries: read failed, error %d
WMI regentries: total %X readed %X:
WMI regentries: total %X readed %X:
[%X] flags %X refcnt %X dev %p prov %X DS %p %s
[%X] flags %X refcnt %X dev %p prov %X DS %p %s
[%X] flags %X refcnt %X cb %p prov %X DS %p %s
[%X] flags %X refcnt %X cb %p prov %X DS %p %s
Etw[%d]:
Etw[%d]:
Type %X Index %X InternalCB %p (%s) %s
Type %X Index %X InternalCB %p (%s) %s
Type %X Index %X InternalCB %p %s
Type %X Index %X InternalCB %p %s
Type %X Index %X InternalCB %p (%s) ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Type %X Index %X InternalCB %p (%s) ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Type %X Index %X InternalCB %p ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Type %X Index %X InternalCB %p ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
dump_Etw: exception occured, code %X
dump_Etw: exception occured, code %X
dump_Etws: exception occured, code %X
dump_Etws: exception occured, code %X
KPRCB.EtwSupport %p:
KPRCB.EtwSupport %p:
KPRCB[%d].EtwSupport %p:
KPRCB[%d].EtwSupport %p:
read_kernel_etws count failed, error %d, ntstatus %X
read_kernel_etws count failed, error %d, ntstatus %X
read_kernel_etws count failed, error %d
read_kernel_etws count failed, error %d
read_kernel_etws: cannot alloc %X bytes
read_kernel_etws: cannot alloc %X bytes
read_kernel_etws failed, error %d, ntstatus %X
read_kernel_etws failed, error %d, ntstatus %X
read_kernel_etws failed, error %d
read_kernel_etws failed, error %d
KEtw[%X]:
KEtw[%X]:
KEtw[%X]: RefCount %d, KProvider - %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
KEtw[%X]: RefCount %d, KProvider - %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
KEtw[%X]: RefCount %d %s
KEtw[%X]: RefCount %d %s
[%X] %p %s
[%X] %p %s
Type %X InUse %d Index %X InternalCB %p (%s) %s
Type %X InUse %d Index %X InternalCB %p (%s) %s
Type %X InUse %d Index %X InternalCB %p %s
Type %X InUse %d Index %X InternalCB %p %s
Type %X InUse %d Index %X InternalCB %p (%s) ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Type %X InUse %d Index %X InternalCB %p (%s) ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Type %X InUse %d Index %X InternalCB %p ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Type %X InUse %d Index %X InternalCB %p ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
EtwCallback[%d] %p %s:
EtwCallback[%d] %p %s:
EtwCallback[%d]:
EtwCallback[%d]:
EtwTrace[%d] %p Ctx %p %s:
EtwTrace[%d] %p Ctx %p %s:
EtwTrace[%d] %p Ctx %p %s - %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
EtwTrace[%d] %p Ctx %p %s - %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
Unknown type %d for Etw[%d]
Unknown type %d for Etw[%d]
DEVINTERFACE_MT_TRANSPORT
DEVINTERFACE_MT_TRANSPORT
DEVINTERFACE_KEYBOARD
DEVINTERFACE_KEYBOARD
DEVINTERFACE_COMPORT
DEVINTERFACE_COMPORT
DEVINTERFACE_VIAMINIPORT
DEVINTERFACE_VIAMINIPORT
DEVINTERFACE_STORAGEPORT
DEVINTERFACE_STORAGEPORT
DEVINTERFACE_IRPORT
DEVINTERFACE_IRPORT
check_pnp_notifiers failed, error %d, status %X
check_pnp_notifiers failed, error %d, status %X
check_pnp_notifiers failed, error %d
check_pnp_notifiers failed, error %d
check_pnp_notifiers: cannot alloc %X bytes (total %d)
check_pnp_notifiers: cannot alloc %X bytes (total %d)
check_pnp_notifiers: read failed, error %d, status %X
check_pnp_notifiers: read failed, error %d, status %X
check_pnp_notifiers: read failed, error %d
check_pnp_notifiers: read failed, error %d
Pnp Notifiers: total %d, readed %d
Pnp Notifiers: total %d, readed %d
Pnp[%d] %p %s %s addr %p
Pnp[%d] %p %s %s addr %p
Pnp[%d] %s %s addr %p %s
Pnp[%d] %s %s addr %p %s
check_pnp_handlers failed, error %d, status %X
check_pnp_handlers failed, error %d, status %X
check_pnp_handlers failed, error %d
check_pnp_handlers failed, error %d
PlugPlayHandlerTable: %d items
PlugPlayHandlerTable: %d items
PlugPlayHandlerTable[%d] %p %s
PlugPlayHandlerTable[%d] %p %s
PlugPlayHandlerTable[%d] %p
PlugPlayHandlerTable[%d] %p
check_sess_notify, error %d, status %X
check_sess_notify, error %d, status %X
check_sess_notify, error %d
check_sess_notify, error %d
check_sess_notify: cannot alloc %X bytes (total %d)
check_sess_notify: cannot alloc %X bytes (total %d)
check_sess_notify: read failed, error %d, status %X
check_sess_notify: read failed, error %d, status %X
check_sess_notify: read failed, error %d
check_sess_notify: read failed, error %d
IopSessionNotifications: %d
IopSessionNotifications: %d
SessionNotifier[%d]: class %d len %X session %p cb %p %s
SessionNotifier[%d]: class %d len %X session %p cb %p %s
check_sess_term_ntfs failed, error %d, status %X
check_sess_term_ntfs failed, error %d, status %X
check_sess_term_ntfs failed, error %d
check_sess_term_ntfs failed, error %d
check_sess_term_ntfs: cannot alloc %X bytes (total %d)
check_sess_term_ntfs: cannot alloc %X bytes (total %d)
check_sess_term_ntfs: read failed, error %d, status %X
check_sess_term_ntfs: read failed, error %d, status %X
check_sess_term_ntfs: read failed, error %d
check_sess_term_ntfs: read failed, error %d
LogonSessionTerminatedRoutines: %d
LogonSessionTerminatedRoutines: %d
[%d] %p %s
[%d] %p %s
check_fs_changes failed, error %d, status %X
check_fs_changes failed, error %d, status %X
check_fs_changes failed, error %d
check_fs_changes failed, error %d
check_fs_changes: cannot alloc %X bytes (total %d)
check_fs_changes: cannot alloc %X bytes (total %d)
check_fs_changes: read failed, error %d, status %X
check_fs_changes: read failed, error %d, status %X
check_fs_changes: read failed, error %d
check_fs_changes: read failed, error %d
FS Change notifiers: %d (actual %d)
FS Change notifiers: %d (actual %d)
DriverObj %p addr %p %s
DriverObj %p addr %p %s
Cannot read count for %s, error %d
Cannot read count for %s, error %d
Count of %s is too big - %X
Count of %s is too big - %X
Cannot read %s table, error %d
Cannot read %s table, error %d
Cannot read entry %d from table of %s, error %d
Cannot read entry %d from table of %s, error %d
check_vista_cmp_list get count failed, error %d, status %X
check_vista_cmp_list get count failed, error %d, status %X
check_vista_cmp_list get count failed, error %d
check_vista_cmp_list get count failed, error %d
check_vista_cmp_list failed, error %d, status %X
check_vista_cmp_list failed, error %d, status %X
check_vista_cmp_list failed, error %d
check_vista_cmp_list failed, error %d
check_ai_cbs: cannot read ExpDisQueryAttributeInformation, error %d, ntstatus %X
check_ai_cbs: cannot read ExpDisQueryAttributeInformation, error %d, ntstatus %X
check_ai_cbs: cannot read ExpDisQueryAttributeInformation, error %d
check_ai_cbs: cannot read ExpDisQueryAttributeInformation, error %d
ExpDisQueryAttributeInformation %p %s
ExpDisQueryAttributeInformation %p %s
check_ai_cbs: cannot read ExpDisSetAttributeInformation, error %d, ntstatus %X
check_ai_cbs: cannot read ExpDisSetAttributeInformation, error %d, ntstatus %X
check_ai_cbs: cannot read ExpDisSetAttributeInformation, error %d
check_ai_cbs: cannot read ExpDisSetAttributeInformation, error %d
ExpDisSetAttributeInformation %p %s
ExpDisSetAttributeInformation %p %s
check_dbgk_lkmd: cannot read DbgkLkmd_cblist, error %d, ntstatus %X
check_dbgk_lkmd: cannot read DbgkLkmd_cblist, error %d, ntstatus %X
check_dbgk_lkmd: cannot read DbgkLkmd_cblist, error %d
check_dbgk_lkmd: cannot read DbgkLkmd_cblist, error %d
DbgkLkmd[%d] callback %p %s
DbgkLkmd[%d] callback %p %s
check_fsrtl: cannot read FltMgrCallbacks, error %d, ntstatus %X
check_fsrtl: cannot read FltMgrCallbacks, error %d, ntstatus %X
check_fsrtl: cannot read FltMgrCallbacks, error %d
check_fsrtl: cannot read FltMgrCallbacks, error %d
FltMgrCallbacks: %p %s
FltMgrCallbacks: %p %s
check_fsrtl: cannot read FsRtlpMupCalls, error %d, ntstatus %X
check_fsrtl: cannot read FsRtlpMupCalls, error %d, ntstatus %X
check_fsrtl: cannot read FsRtlpMupCalls, error %d
check_fsrtl: cannot read FsRtlpMupCalls, error %d
FsRtlpMupCalls: %p %s
FsRtlpMupCalls: %p %s
check_Iof: cannot read pIofCallDriver, error %d, ntstatus %X
check_Iof: cannot read pIofCallDriver, error %d, ntstatus %X
check_Iof: cannot read pIofCallDriver, error %d
check_Iof: cannot read pIofCallDriver, error %d
pIofCallDriver %p patched by %s
pIofCallDriver %p patched by %s
check_Iof: cannot read pIofCompleteRequest, error %d, ntstatus %X
check_Iof: cannot read pIofCompleteRequest, error %d, ntstatus %X
check_Iof: cannot read pIofCompleteRequest, error %d
check_Iof: cannot read pIofCompleteRequest, error %d
pIofCompleteRequest %p patched by %s
pIofCompleteRequest %p patched by %s
check_Iof: cannot read pIoAllocateIrp, error %d, ntstatus %X
check_Iof: cannot read pIoAllocateIrp, error %d, ntstatus %X
check_Iof: cannot read pIoAllocateIrp, error %d
check_Iof: cannot read pIoAllocateIrp, error %d
pIoAllocateIrp %p patched by %s
pIoAllocateIrp %p patched by %s
check_Iof: cannot read pIoFreeIrp, error %d, ntstatus %X
check_Iof: cannot read pIoFreeIrp, error %d, ntstatus %X
check_Iof: cannot read pIoFreeIrp, error %d
check_Iof: cannot read pIoFreeIrp, error %d
pIoFreeIrp %p patched by %s
pIoFreeIrp %p patched by %s
check_Iof: cannot read HvlpHypercallCodeVa, error %d, ntstatus %X
check_Iof: cannot read HvlpHypercallCodeVa, error %d, ntstatus %X
check_Iof: cannot read HvlpHypercallCodeVa, error %d
check_Iof: cannot read HvlpHypercallCodeVa, error %d
HvlpHypercallCodeVa %p patched by %s
HvlpHypercallCodeVa %p patched by %s
%SystemRoot%\System32\sxssrv.dll
%SystemRoot%\System32\sxssrv.dll
%SystemRoot%\System32\csrsrv.dll
%SystemRoot%\System32\csrsrv.dll
%SystemRoot%\System32\basesrv.dll
%SystemRoot%\System32\basesrv.dll
%SystemRoot%\System32\winsrv.dll
%SystemRoot%\System32\winsrv.dll
%SystemRoot%\System32\lsasrv.dll
%SystemRoot%\System32\lsasrv.dll
%SystemRoot%\System32\ntdll.dll
%SystemRoot%\System32\ntdll.dll
KiDebugRoutine %p hooked by %s
KiDebugRoutine %p hooked by %s
PspLegoNotifyRoutine %p hooked by %s
PspLegoNotifyRoutine %p hooked by %s
KiTimeUpdateNotifyRoutine %p hooked by %s
KiTimeUpdateNotifyRoutine %p hooked by %s
KiSwapContextNotifyRoutine %p hooked by %s
KiSwapContextNotifyRoutine %p hooked by %s
KiThreadSelectNotifyRoutine %p hooked by %s
KiThreadSelectNotifyRoutine %p hooked by %s
Sysenter patched, addr %p not in %s !!!
Sysenter patched, addr %p not in %s !!!
Mailslot: %S
Mailslot: %S
NamedPipe: %S
NamedPipe: %S
DEVCLASS_MULTIPORTSERIAL
DEVCLASS_MULTIPORTSERIAL
DEVCLASS_PORTS
DEVCLASS_PORTS
DEVCLASS_KEYBOARD
DEVCLASS_KEYBOARD
DEVCLASS_APMSUPPORT
DEVCLASS_APMSUPPORT
read_dev_chrs(%S) failed, ntstatus %X
read_dev_chrs(%S) failed, ntstatus %X
DrvObj %p name %S %s
DrvObj %p name %S %s
DrvObj %p nameLen %X %s
DrvObj %p nameLen %X %s
dev_props failed, status %X
dev_props failed, status %X
ClassGUID: %S
ClassGUID: %S
ClassGUID: %S - %s
ClassGUID: %S - %s
Cannot open directory %S, error %X
Cannot open directory %S, error %X
Cannot realloc %d bytes
Cannot realloc %d bytes
Cannot open device directory, error %X
Cannot open device directory, error %X
Cannot open driver directory, error %X
Cannot open driver directory, error %X
Cannot open FileSystem directory, error %X
Cannot open FileSystem directory, error %X
Unknown HAL private dispatch table version %X
Unknown HAL private dispatch table version %X
HalAcpiTimerInit: %p %s
HalAcpiTimerInit: %p %s
HalAcpiTimerCarry: %p %s
HalAcpiTimerCarry: %p %s
HalAcpiMachineStateInit: %p %s
HalAcpiMachineStateInit: %p %s
HalAcpiQueryFlags: %p %s
HalAcpiQueryFlags: %p %s
HalAcpiPicStateIntact: %p %s
HalAcpiPicStateIntact: %p %s
HalRestoreInterruptControllerState: %p %s
HalRestoreInterruptControllerState: %p %s
HalPciInterfaceReadConfig: %p %s
HalPciInterfaceReadConfig: %p %s
HalPciInterfaceWriteConfig: %p %s
HalPciInterfaceWriteConfig: %p %s
HalSetVectorState: %p %s
HalSetVectorState: %p %s
HalGetApicVersion: %p %s
HalGetApicVersion: %p %s
HalSetMaxLegacyPciBusNumber: %p %s
HalSetMaxLegacyPciBusNumber: %p %s
HalIsVectorValid: %p %s
HalIsVectorValid: %p %s
HalAcpiGetTableDispatch: %p %s
HalAcpiGetTableDispatch: %p %s
HalAcpiGetRsdpDispatch: %p %s
HalAcpiGetRsdpDispatch: %p %s
HalAcpiGetFacsMappingDispatch: %p %s
HalAcpiGetFacsMappingDispatch: %p %s
HalAcpiGetAllTablesDispatch: %p %s
HalAcpiGetAllTablesDispatch: %p %s
HalAcpiPmRegisterAvailable: %p %s
HalAcpiPmRegisterAvailable: %p %s
HalAcpiPmRegisterRead: %p %s
HalAcpiPmRegisterRead: %p %s
HalAcpiPmRegisterWrite: %p %s
HalAcpiPmRegisterWrite: %p %s
HalHandlerForBus: %p %s
HalHandlerForBus: %p %s
HalHandlerForConfigSpace: %p %s
HalHandlerForConfigSpace: %p %s
HalLocateHiberRanges: %p %s
HalLocateHiberRanges: %p %s
HalRegisterBusHandler: %p %s
HalRegisterBusHandler: %p %s
HalSetWakeEnable: %p %s
HalSetWakeEnable: %p %s
HalSetWakeAlarm: %p %s
HalSetWakeAlarm: %p %s
HalPciTranslateBusAddress: %p %s
HalPciTranslateBusAddress: %p %s
HalPciAssignSlotResources: %p %s
HalPciAssignSlotResources: %p %s
HalHaltSystem: %p %s
HalHaltSystem: %p %s
HalFindBusAddressTranslation: %p %s
HalFindBusAddressTranslation: %p %s
HalResetDisplay: %p %s
HalResetDisplay: %p %s
HalHandlerForBus: %p %s
HalHandlerForBus: %p %s
HalHandlerForConfigSpace: %p %s
HalHandlerForConfigSpace: %p %s
HalLocateHiberRanges: %p %s
HalLocateHiberRanges: %p %s
HalRegisterBusHandler: %p %s
HalRegisterBusHandler: %p %s
HalSetWakeEnable: %p %s
HalSetWakeEnable: %p %s
HalSetWakeAlarm: %p %s
HalSetWakeAlarm: %p %s
HalPciTranslateBusAddress: %p %s
HalPciTranslateBusAddress: %p %s
HalPciAssignSlotResources: %p %s
HalPciAssignSlotResources: %p %s
HalHaltSystem: %p %s
HalHaltSystem: %p %s
HalFindBusAddressTranslation: %p %s
HalFindBusAddressTranslation: %p %s
HalResetDisplay: %p %s
HalResetDisplay: %p %s
KdSetupPciDeviceForDebugging: %p %s
KdSetupPciDeviceForDebugging: %p %s
KdReleasePciDeviceforDebugging: %p %s
KdReleasePciDeviceforDebugging: %p %s
KdGetAcpiTablePhase0: %p %s
KdGetAcpiTablePhase0: %p %s
KdCheckPowerButton: %p %s
KdCheckPowerButton: %p %s
HalVectorToIDTEntry: %p %s
HalVectorToIDTEntry: %p %s
KdMapPhysicalMemory64: %p %s
KdMapPhysicalMemory64: %p %s
KdUnmapVirtualAddress: %p %s
KdUnmapVirtualAddress: %p %s
HalMmMemoryUsage: %p %s
HalMmMemoryUsage: %p %s
HalAllocateMapRegisters: %p %s
HalAllocateMapRegisters: %p %s
KdGetPciDataByOffset: %p %s
KdGetPciDataByOffset: %p %s
KdSetPciDataByOffset: %p %s
KdSetPciDataByOffset: %p %s
HalGetInterruptVector: %p %s
HalGetInterruptVector: %p %s
HalGetVectorInput: %p %s
HalGetVectorInput: %p %s
HalLoadMicrocode: %p %s
HalLoadMicrocode: %p %s
HalUnloadMicrocode: %p %s
HalUnloadMicrocode: %p %s
HalMcUpdatePostUpdate: %p %s
HalMcUpdatePostUpdate: %p %s
HalAllocateMessageTarget: %p %s
HalAllocateMessageTarget: %p %s
HalFreeMessageTarget: %p %s
HalFreeMessageTarget: %p %s
HalDpReplaceBegin: %p %s
HalDpReplaceBegin: %p %s
HalDpReplaceTarget: %p %s
HalDpReplaceTarget: %p %s
HalDpReplaceControl: %p %s
HalDpReplaceControl: %p %s
HalDpReplaceEnd: %p %s
HalDpReplaceEnd: %p %s
HalPrepareForBugcheck: %p %s
HalPrepareForBugcheck: %p %s
HalQueryWakeTime: %p %s
HalQueryWakeTime: %p %s
HalReportIdleStateUsage: %p %s
HalReportIdleStateUsage: %p %s
HalHandlerForBus: %p %s
HalHandlerForBus: %p %s
HalHandlerForConfigSpace: %p %s
HalHandlerForConfigSpace: %p %s
HalLocateHiberRanges: %p %s
HalLocateHiberRanges: %p %s
HalRegisterBusHandler: %p %s
HalRegisterBusHandler: %p %s
HalSetWakeEnable: %p %s
HalSetWakeEnable: %p %s
HalSetWakeAlarm: %p %s
HalSetWakeAlarm: %p %s
HalPciTranslateBusAddress: %p %s
HalPciTranslateBusAddress: %p %s
HalPciAssignSlotResources: %p %s
HalPciAssignSlotResources: %p %s
HalHaltSystem: %p %s
HalHaltSystem: %p %s
HalFindBusAddressTranslation: %p %s
HalFindBusAddressTranslation: %p %s
HalResetDisplay: %p %s
HalResetDisplay: %p %s
HalAllocateMapRegisters: %p %s
HalAllocateMapRegisters: %p %s
KdSetupPciDeviceForDebugging: %p %s
KdSetupPciDeviceForDebugging: %p %s
KdReleasePciDeviceforDebugging: %p %s
KdReleasePciDeviceforDebugging: %p %s
KdGetAcpiTablePhase0: %p %s
KdGetAcpiTablePhase0: %p %s
KdCheckPowerButton: %p %s
KdCheckPowerButton: %p %s
HalVectorToIDTEntry: %p %s
HalVectorToIDTEntry: %p %s
KdMapPhysicalMemory64: %p %s
KdMapPhysicalMemory64: %p %s
KdUnmapVirtualAddress: %p %s
KdUnmapVirtualAddress: %p %s
KdGetPciDataByOffset: %p %s
KdGetPciDataByOffset: %p %s
KdSetPciDataByOffset: %p %s
KdSetPciDataByOffset: %p %s
HalGetInterruptVector: %p %s
HalGetInterruptVector: %p %s
HalGetVectorInput: %p %s
HalGetVectorInput: %p %s
HalLoadMicrocode: %p %s
HalLoadMicrocode: %p %s
HalUnloadMicrocode: %p %s
HalUnloadMicrocode: %p %s
HalMcUpdatePostUpdate: %p %s
HalMcUpdatePostUpdate: %p %s
HalAllocateMessageTarget: %p %s
HalAllocateMessageTarget: %p %s
HalFreeMessageTarget: %p %s
HalFreeMessageTarget: %p %s
HalDpReplaceBegin: %p %s
HalDpReplaceBegin: %p %s
HalDpReplaceTarget: %p %s
HalDpReplaceTarget: %p %s
HalDpReplaceControl: %p %s
HalDpReplaceControl: %p %s
HalDpReplaceEnd: %p %s
HalDpReplaceEnd: %p %s
HalPrepareForBugcheck: %p %s
HalPrepareForBugcheck: %p %s
HalQueryWakeTime: %p %s
HalQueryWakeTime: %p %s
HalReportIdleStateUsage: %p %s
HalReportIdleStateUsage: %p %s
HalTscSynchronization: %p %s
HalTscSynchronization: %p %s
HalWheaInitProcessorGenericSection: %p %s
HalWheaInitProcessorGenericSection: %p %s
HalStopLegacyUsbInterrupts: %p %s
HalStopLegacyUsbInterrupts: %p %s
HalReadWheaPhysicalMemory: %p %s
HalReadWheaPhysicalMemory: %p %s
HalWriteWheaPhysicalMemory: %p %s
HalWriteWheaPhysicalMemory: %p %s
HalDpMaskLevelTriggeredInterrupts: %p %s
HalDpMaskLevelTriggeredInterrupts: %p %s
HalDpUnmaskLevelTriggeredInterrupts: %p %s
HalDpUnmaskLevelTriggeredInterrupts: %p %s
HalDpGetInterruptReplayState: %p %s
HalDpGetInterruptReplayState: %p %s
HalDpReplayInterrupts: %p %s
HalDpReplayInterrupts: %p %s
HalQueryIoPortAccessSupported: %p %s
HalQueryIoPortAccessSupported: %p %s
HalHandlerForBus: %p %s
HalHandlerForBus: %p %s
HalHandlerForConfigSpace: %p %s
HalHandlerForConfigSpace: %p %s
HalLocateHiberRanges: %p %s
HalLocateHiberRanges: %p %s
HalRegisterBusHandler: %p %s
HalRegisterBusHandler: %p %s
HalSetWakeEnable: %p %s
HalSetWakeEnable: %p %s
HalSetWakeAlarm: %p %s
HalSetWakeAlarm: %p %s
HalPciTranslateBusAddress: %p %s
HalPciTranslateBusAddress: %p %s
HalPciAssignSlotResources: %p %s
HalPciAssignSlotResources: %p %s
HalHaltSystem: %p %s
HalHaltSystem: %p %s
HalFindBusAddressTranslation: %p %s
HalFindBusAddressTranslation: %p %s
HalResetDisplay: %p %s
HalResetDisplay: %p %s
HalAllocateMapRegisters: %p %s
HalAllocateMapRegisters: %p %s
KdSetupPciDeviceForDebugging: %p %s
KdSetupPciDeviceForDebugging: %p %s
KdReleasePciDeviceforDebugging: %p %s
KdReleasePciDeviceforDebugging: %p %s
KdGetAcpiTablePhase0: %p %s
KdGetAcpiTablePhase0: %p %s
KdCheckPowerButton: %p %s
KdCheckPowerButton: %p %s
HalVectorToIDTEntry: %p %s
HalVectorToIDTEntry: %p %s
KdMapPhysicalMemory64: %p %s
KdMapPhysicalMemory64: %p %s
KdUnmapVirtualAddress: %p %s
KdUnmapVirtualAddress: %p %s
KdGetPciDataByOffset: %p %s
KdGetPciDataByOffset: %p %s
KdSetPciDataByOffset: %p %s
KdSetPciDataByOffset: %p %s
HalGetInterruptVector: %p %s
HalGetInterruptVector: %p %s
HalGetVectorInput: %p %s
HalGetVectorInput: %p %s
HalLoadMicrocode: %p %s
HalLoadMicrocode: %p %s
HalUnloadMicrocode: %p %s
HalUnloadMicrocode: %p %s
HalMcUpdatePostUpdate: %p %s
HalMcUpdatePostUpdate: %p %s
HalAllocateMessageTarget: %p %s
HalAllocateMessageTarget: %p %s
HalFreeMessageTarget: %p %s
HalFreeMessageTarget: %p %s
HalDpReplaceBegin: %p %s
HalDpReplaceBegin: %p %s
HalDpReplaceTarget: %p %s
HalDpReplaceTarget: %p %s
HalDpReplaceControl: %p %s
HalDpReplaceControl: %p %s
HalDpReplaceEnd: %p %s
HalDpReplaceEnd: %p %s
HalPrepareForBugcheck: %p %s
HalPrepareForBugcheck: %p %s
HalQueryWakeTime: %p %s
HalQueryWakeTime: %p %s
HalReportIdleStateUsage: %p %s
HalReportIdleStateUsage: %p %s
HalTscSynchronization: %p %s
HalTscSynchronization: %p %s
HalWheaInitProcessorGenericSection: %p %s
HalWheaInitProcessorGenericSection: %p %s
HalStopLegacyUsbInterrupts: %p %s
HalStopLegacyUsbInterrupts: %p %s
HalReadWheaPhysicalMemory: %p %s
HalReadWheaPhysicalMemory: %p %s
HalWriteWheaPhysicalMemory: %p %s
HalWriteWheaPhysicalMemory: %p %s
HalInterruptMaskLevelTriggeredLines: %p %s
HalInterruptMaskLevelTriggeredLines: %p %s
HalInterruptUnmaskLevelTriggeredLines: %p %s
HalInterruptUnmaskLevelTriggeredLines: %p %s
HalDpGetInterruptReplayState: %p %s
HalDpGetInterruptReplayState: %p %s
HalDpReplayInterrupts: %p %s
HalDpReplayInterrupts: %p %s
HalQueryIoPortAccessSupported: %p %s
HalQueryIoPortAccessSupported: %p %s
KdSetupIntegratedDeviceForDebugging: %p %s
KdSetupIntegratedDeviceForDebugging: %p %s
KdReleaseIntegratedDeviceForDebugging: %p %s
KdReleaseIntegratedDeviceForDebugging: %p %s
HalEnlightenmentInitialize: %p %s
HalEnlightenmentInitialize: %p %s
HalAllocateEarlyPages: %p %s
HalAllocateEarlyPages: %p %s
HalMapEarlyPages: %p %s
HalMapEarlyPages: %p %s
HalTimerGetClockOwner: %p %s
HalTimerGetClockOwner: %p %s
HalTimerGetClockConfiguration: %p %s
HalTimerGetClockConfiguration: %p %s
HalTimerNotifyProcessorFreeze: %p %s
HalTimerNotifyProcessorFreeze: %p %s
HalTimerPrepareProcessorForIdle: %p %s
HalTimerPrepareProcessorForIdle: %p %s
HalDiagRegisterLogRoutine: %p %s
HalDiagRegisterLogRoutine: %p %s
HalTimerResumeProcessorFromIdle: %p %s
HalTimerResumeProcessorFromIdle: %p %s
HalTimerResetLastClockTick: %p %s
HalTimerResetLastClockTick: %p %s
HalVectorToIDTEntryEx: %p %s
HalVectorToIDTEntryEx: %p %s
HalSecondaryInterruptQueryPrimaryInformation: %p %s
HalSecondaryInterruptQueryPrimaryInformation: %p %s
HalMaskInterrupt: %p %s
HalMaskInterrupt: %p %s
HalUnmaskInterrupt: %p %s
HalUnmaskInterrupt: %p %s
HalIsInterruptTypeSecondary: %p %s
HalIsInterruptTypeSecondary: %p %s
HalAllocateGsivForSecondaryInterrupt: %p %s
HalAllocateGsivForSecondaryInterrupt: %p %s
HalAddInterruptRemapping: %p %s
HalAddInterruptRemapping: %p %s
HalRemoveInterruptRemapping: %p %s
HalRemoveInterruptRemapping: %p %s
HalSaveAndDisableEnlightenment: %p %s
HalSaveAndDisableEnlightenment: %p %s
HalRestoreHvEnlightenment: %p %s
HalRestoreHvEnlightenment: %p %s
HalPciEarlyRestore: %p %s
HalPciEarlyRestore: %p %s
HalInterruptGetLocalIdentifier: %p %s
HalInterruptGetLocalIdentifier: %p %s
HalAllocatePmcCounterSet: %p %s
HalAllocatePmcCounterSet: %p %s
HalCollectPmcCounters: %p %s
HalCollectPmcCounters: %p %s
HalFreePmcCounterSet: %p %s
HalFreePmcCounterSet: %p %s
HalTimerQueryCycleCounter: %p %s
HalTimerQueryCycleCounter: %p %s
HalTimerGetNextTickDuration: %p %s
HalTimerGetNextTickDuration: %p %s
HalPciMarkHiberPhase: %p %s
HalPciMarkHiberPhase: %p %s
HalInterruptQueryProcessorRestartEntryPoint: %p %s
HalInterruptQueryProcessorRestartEntryPoint: %p %s
HalInterruptRequestSecondaryInterrupt: %p %s
HalInterruptRequestSecondaryInterrupt: %p %s
HalInterruptEnumerateUnmaskedInterrupts: %p %s
HalInterruptEnumerateUnmaskedInterrupts: %p %s
HalBiosDisplayReset: %p %s
HalBiosDisplayReset: %p %s
HalGetDmaAdapter: %p %s
HalGetDmaAdapter: %p %s
HalCheckPowerButton: %p %s
HalCheckPowerButton: %p %s
HalMapPhysicalMemoryWriteThrough64: %p %s
HalMapPhysicalMemoryWriteThrough64: %p %s
HalUnmapVirtualAddress: %p %s
HalUnmapVirtualAddress: %p %s
HalKdReadPCIConfig: %p %s
HalKdReadPCIConfig: %p %s
HalKdWritePCIConfig: %p %s
HalKdWritePCIConfig: %p %s
HalTimerQueryWakeTime: %p %s
HalTimerQueryWakeTime: %p %s
HalTimerReportIdleStateUsage: %p %s
HalTimerReportIdleStateUsage: %p %s
HalKdEnumerateDebuggingDevices: %p %s
HalKdEnumerateDebuggingDevices: %p %s
HalFlushIoRectangleExternalCache: %p %s
HalFlushIoRectangleExternalCache: %p %s
HalPowerEarlyRestore: %p %s
HalPowerEarlyRestore: %p %s
HalQueryCapsuleCapabilities: %p %s
HalQueryCapsuleCapabilities: %p %s
HalUpdateCapsule: %p %s
HalUpdateCapsule: %p %s
HalPciMultiStageResumeCapable: %p %s
HalPciMultiStageResumeCapable: %p %s
check_hal_private_disp_table: cannot read table, error %d, ntstatus %X
check_hal_private_disp_table: cannot read table, error %d, ntstatus %X
check_hal_private_disp_table: cannot read table, error %d
check_hal_private_disp_table: cannot read table, error %d
check_hal_disp_table: cannot read table, error %d, ntstatus %X
check_hal_disp_table: cannot read table, error %d, ntstatus %X
check_hal_disp_table: cannot read table, error %d
check_hal_disp_table: cannot read table, error %d
HalQuerySystemInformation: %p %s
HalQuerySystemInformation: %p %s
HalSetSystemInformation: %p %s
HalSetSystemInformation: %p %s
HalQueryBusSlots: %p %s
HalQueryBusSlots: %p %s
HalExamineMBR: %p %s
HalExamineMBR: %p %s
HalIoReadPartitionTable: %p %s
HalIoReadPartitionTable: %p %s
HalIoSetPartitionInformation: %p %s
HalIoSetPartitionInformation: %p %s
HalIoWritePartitionTable: %p %s
HalIoWritePartitionTable: %p %s
HalReferenceHandlerForBus %p %s
HalReferenceHandlerForBus %p %s
HalReferenceBusHandler %p %s
HalReferenceBusHandler %p %s
HalDereferenceBusHandler %p %s
HalDereferenceBusHandler %p %s
HalInitPnpDriver %p %s
HalInitPnpDriver %p %s
HalInitPowerManagement %p %s
HalInitPowerManagement %p %s
HalGetDmaAdapter %p %s
HalGetDmaAdapter %p %s
HalGetInterruptTranslator %p %s
HalGetInterruptTranslator %p %s
HalStartMirroring %p %s
HalStartMirroring %p %s
HalEndMirroring %p %s
HalEndMirroring %p %s
HalMirrorPhysicalMemory %p %s
HalMirrorPhysicalMemory %p %s
HalEndOfBoot %p %s
HalEndOfBoot %p %s
HalMirrorVerify %p %s
HalMirrorVerify %p %s
HalGetCachedAcpiTable %p %s
HalGetCachedAcpiTable %p %s
HalSetPciErrorHandlerCallback %p %s
HalSetPciErrorHandlerCallback %p %s
read_hal_apci_disp_table return %X bytes, error %d, ntstatus %X
read_hal_apci_disp_table return %X bytes, error %d, ntstatus %X
read_hal_apci_disp_table return %X bytes, error %d
read_hal_apci_disp_table return %X bytes, error %d
Bad HalAcpiDispatchTable version: %X
Bad HalAcpiDispatchTable version: %X
read_gdt_size failed, error %d, ntstatus %X
read_gdt_size failed, error %d, ntstatus %X
read_gdt_size failed, error %d
read_gdt_size failed, error %d
Cannot alloc %d bytes for GDT entries
Cannot alloc %d bytes for GDT entries
read_gdt failed, error %d, ntstatus %X
read_gdt failed, error %d, ntstatus %X
read_gdt failed, error %d
read_gdt failed, error %d
Descriptor[%d] %s S %d DPL %d type %X base %X limit %X
Descriptor[%d] %s S %d DPL %d type %X base %X limit %X
WinChecker::dump_ldt failed, error %X, ntstatus %X
WinChecker::dump_ldt failed, error %X, ntstatus %X
WinChecker::dump_ldt failed, error %X
WinChecker::dump_ldt failed, error %X
WinChecker::dump_ldt: cannot alloc ldt array, size %X
WinChecker::dump_ldt: cannot alloc ldt array, size %X
Ldt[%d]:
Ldt[%d]:
Base: X
Base: X
Limit: X
Limit: X
AVL: %d
AVL: %d
D/B: %d
D/B: %d
DPL: %d
DPL: %d
G: %d
G: %d
P: %d
P: %d
S: %d
S: %d
Type: %d
Type: %d
Cannot read code for kinterrupt(%X) thunk, error %d
Cannot read code for kinterrupt(%X) thunk, error %d
IDT patched: unknown type %X selector %X addr %p for int%X
IDT patched: unknown type %X selector %X addr %p for int%X
IDT patched: unknown selector %X for int%X
IDT patched: unknown selector %X for int%X
IDT patched: int%X has unknown selector %X base %X limit %X addr %p
IDT patched: int%X has unknown selector %X base %X limit %X addr %p
IDT patched: int%X addr %p by module %s
IDT patched: int%X addr %p by module %s
IDT int%X addr %p KINTERRUPT %p
IDT int%X addr %p KINTERRUPT %p
IDT patched: int%X addr %p
IDT patched: int%X addr %p
Int%X: selector %X type TASK DPL %X base %X limit %X
Int%X: selector %X type TASK DPL %X base %X limit %X
Int%X: selector %X type %X DPL %X addr %p base %X limit %X
Int%X: selector %X type %X DPL %X addr %p base %X limit %X
Int%X: selector %X type %X DPL %X addr %p
Int%X: selector %X type %X DPL %X addr %p
read_idt_size failed, error %d, ntstatus %X
read_idt_size failed, error %d, ntstatus %X
read_idt_size failed, error %d
read_idt_size failed, error %d
read_idt: cannot alloc %d bytes for IDT storage
read_idt: cannot alloc %d bytes for IDT storage
read_idt failed, error %d, ntstatus %X
read_idt failed, error %d, ntstatus %X
read_idt failed, error %d
read_idt failed, error %d
Cannot read kinterrupt (%X), error %d
Cannot read kinterrupt (%X), error %d
KInterrupt %X (%p):
KInterrupt %X (%p):
Size %X type %X
Size %X type %X
ServiceRoutine %p %s
ServiceRoutine %p %s
DispatchAddress %p %s
DispatchAddress %p %s
check_ob_types: cannot read size of ObTypes list, error %d, ntstatus %X
check_ob_types: cannot read size of ObTypes list, error %d, ntstatus %X
check_ob_types: cannot read size of ObTypes list, error %d
check_ob_types: cannot read size of ObTypes list, error %d
check_ob_types: cannot read %d bytes (readed %d), error %d, ntstatus %X
check_ob_types: cannot read %d bytes (readed %d), error %d, ntstatus %X
check_ob_types: cannot read %d bytes (readed %d), error %d
check_ob_types: cannot read %d bytes (readed %d), error %d
fill_ob_type: cannot read ObType %S (%X), error %d
fill_ob_type: cannot read ObType %S (%X), error %d
Cannot read ObType %S (%X), error %d
Cannot read ObType %S (%X), error %d
ObType %S:
ObType %S:
DumpProcedure: %p %s
DumpProcedure: %p %s
OpenProcedure: %p %s
OpenProcedure: %p %s
CloseProcedure: %p %s
CloseProcedure: %p %s
DeleteProcedure: %p %s
DeleteProcedure: %p %s
ParseProcedure: %p %s
ParseProcedure: %p %s
SecurityProcedure: %p %s
SecurityProcedure: %p %s
QueryNameProcedure: %p %s
QueryNameProcedure: %p %s
OkayToCloseProcedure: %p %s
OkayToCloseProcedure: %p %s
ZwAlpcConnectPortEx
ZwAlpcConnectPortEx
ZwOpenKeyTransactedEx
ZwOpenKeyTransactedEx
ZwOpenKeyEx
ZwOpenKeyEx
ZwOpenKeyTransacted
ZwOpenKeyTransacted
ZwCreateKeyTransacted
ZwCreateKeyTransacted
ZwAlpcSendWaitReceivePort
ZwAlpcSendWaitReceivePort
ZwAlpcImpersonateClientOfPort
ZwAlpcImpersonateClientOfPort
ZwAlpcDisconnectPort
ZwAlpcDisconnectPort
ZwAlpcDeletePortSection
ZwAlpcDeletePortSection
ZwAlpcCreatePortSection
ZwAlpcCreatePortSection
ZwAlpcCreatePort
ZwAlpcCreatePort
ZwAlpcConnectPort
ZwAlpcConnectPort
ZwAlpcAcceptConnectPort
ZwAlpcAcceptConnectPort
ZwUnloadKey2
ZwUnloadKey2
ZwQueryOpenSubKeysEx
ZwQueryOpenSubKeysEx
ZwLoadKeyEx
ZwLoadKeyEx
ZwQueryPortInformationProcess
ZwQueryPortInformationProcess
ZwWaitForKeyedEvent
ZwWaitForKeyedEvent
ZwReleaseKeyedEvent
ZwReleaseKeyedEvent
ZwOpenKeyedEvent
ZwOpenKeyedEvent
ZwCreateKeyedEvent
ZwCreateKeyedEvent
ZwUnloadKeyEx
ZwUnloadKeyEx
ZwSaveKeyEx
ZwSaveKeyEx
ZwRenameKey
ZwRenameKey
ZwLockRegistryKey
ZwLockRegistryKey
ZwLockProductActivationKeys
ZwLockProductActivationKeys
ZwCompressKey
ZwCompressKey
ZwCompactKeys
ZwCompactKeys
ZwYieldExecution
ZwYieldExecution
ZwUnloadKey
ZwUnloadKey
ZwSetValueKey
ZwSetValueKey
ZwSetThreadExecutionState
ZwSetThreadExecutionState
ZwSetInformationKey
ZwSetInformationKey
ZwSetDefaultHardErrorPort
ZwSetDefaultHardErrorPort
ZwSecureConnectPort
ZwSecureConnectPort
ZwSaveMergedKeys
ZwSaveMergedKeys
ZwSaveKey
ZwSaveKey
ZwRestoreKey
ZwRestoreKey
ZwRequestWaitReplyPort
ZwRequestWaitReplyPort
ZwRequestPort
ZwRequestPort
ZwReplyWaitReplyPort
ZwReplyWaitReplyPort
ZwReplyWaitReceivePortEx
ZwReplyWaitReceivePortEx
ZwReplyWaitReceivePort
ZwReplyWaitReceivePort
ZwReplyPort
ZwReplyPort
ZwReplaceKey
ZwReplaceKey
ZwRegisterThreadTerminatePort
ZwRegisterThreadTerminatePort
ZwQueryValueKey
ZwQueryValueKey
ZwQueryOpenSubKeys
ZwQueryOpenSubKeys
ZwQueryMultipleValueKey
ZwQueryMultipleValueKey
ZwQueryKey
ZwQueryKey
ZwQueryInformationPort
ZwQueryInformationPort
ZwOpenKey
ZwOpenKey
ZwNotifyChangeMultipleKeys
ZwNotifyChangeMultipleKeys
ZwNotifyChangeKey
ZwNotifyChangeKey
ZwLoadKey2
ZwLoadKey2
ZwLoadKey
ZwLoadKey
ZwListenPort
ZwListenPort
ZwImpersonateClientOfPort
ZwImpersonateClientOfPort
ZwFlushKey
ZwFlushKey
ZwEnumerateValueKey
ZwEnumerateValueKey
ZwEnumerateKey
ZwEnumerateKey
ZwDeleteValueKey
ZwDeleteValueKey
ZwDeleteKey
ZwDeleteKey
ZwDelayExecution
ZwDelayExecution
ZwCreateWaitablePort
ZwCreateWaitablePort
ZwCreatePort
ZwCreatePort
ZwCreateNamedPipeFile
ZwCreateNamedPipeFile
ZwCreateKey
ZwCreateKey
ZwConnectPort
ZwConnectPort
ZwCompleteConnectPort
ZwCompleteConnectPort
ZwAcceptConnectPort
ZwAcceptConnectPort
FindKiServiceTable: relocation type %d found at X
FindKiServiceTable: relocation type %d found at X
Cannot read body of %s !
Cannot read body of %s !
Cannot extract index of %s, error %d
Cannot extract index of %s, error %d
kernel %s don`t contains KeServiceDescriptorTable function !
kernel %s don`t contains KeServiceDescriptorTable function !
Cannot find SDT in %s
Cannot find SDT in %s
Cannot read ntdll.dll
Cannot read ntdll.dll
Cannot read body of %s!
Cannot read body of %s!
Cannot read body of ZwYieldExecution!
Cannot read body of ZwYieldExecution!
Cannot extract index of ZwYieldExecution, error %d
Cannot extract index of ZwYieldExecution, error %d
Cannot extract index of ZwPlugPlayControl , error %d
Cannot extract index of ZwPlugPlayControl , error %d
%s: %p
%s: %p
SDT entry %X (%s) hooked %p %s!
SDT entry %X (%s) hooked %p %s!
SDT entry %X hooked %p %s!
SDT entry %X hooked %p %s!
Need unhook %d items in SSDT
Need unhook %d items in SSDT
UNHOOK_ITEM: Index %X Offset %X
UNHOOK_ITEM: Index %X Offset %X
Unhook SSDT failed, lasterror %d
Unhook SSDT failed, lasterror %d
Unhooked %d SSDT items
Unhooked %d SSDT items
NtUserSetProcessRestrictionExemption
NtUserSetProcessRestrictionExemption
NtUserAcquireIAMKey
NtUserAcquireIAMKey
NtGdiDdDDICreateKeyedMutex2
NtGdiDdDDICreateKeyedMutex2
NtGdiDdDDIOpenKeyedMutex2
NtGdiDdDDIOpenKeyedMutex2
NtGdiDdDDIAcquireKeyedMutex2
NtGdiDdDDIAcquireKeyedMutex2
NtGdiDdDDIReleaseKeyedMutex2
NtGdiDdDDIReleaseKeyedMutex2
NtUserSetTHQAPublicKey
NtUserSetTHQAPublicKey
NtGdiDdDDIReleaseKeyedMutex
NtGdiDdDDIReleaseKeyedMutex
NtGdiDdDDIAcquireKeyedMutex
NtGdiDdDDIAcquireKeyedMutex
NtGdiDdDDIDestroyKeyedMutex
NtGdiDdDDIDestroyKeyedMutex
NtGdiDdDDIOpenKeyedMutex
NtGdiDdDDIOpenKeyedMutex
NtGdiDdDDICreateKeyedMutex
NtGdiDdDDICreateKeyedMutex
NtUserEndTouchOperation
NtUserEndTouchOperation
NtUserSfmDxReportPendingBindingsToDwm
NtUserSfmDxReportPendingBindingsToDwm
NtGdiDDCCIGetTimingReport
NtGdiDDCCIGetTimingReport
NtUserUnregisterSessionPort
NtUserUnregisterSessionPort
NtUserRegisterSessionPort
NtUserRegisterSessionPort
NtUserRegisterErrorReportingDialog
NtUserRegisterErrorReportingDialog
NtGdiSetOPMSigningKeyAndSequenceNumbers
NtGdiSetOPMSigningKeyAndSequenceNumbers
NtGdiGetCertificateSize
NtGdiGetCertificateSize
NtGdiGetCertificate
NtGdiGetCertificate
NtUserWaitForMsgAndEvent
NtUserWaitForMsgAndEvent
NtUserVkKeyScanEx
NtUserVkKeyScanEx
NtUserUnregisterHotKey
NtUserUnregisterHotKey
NtUserUnlockWindowStation
NtUserUnlockWindowStation
NtUserUnloadKeyboardLayout
NtUserUnloadKeyboardLayout
NtUserUnhookWindowsHookEx
NtUserUnhookWindowsHookEx
NtUserSetWindowStationUser
NtUserSetWindowStationUser
NtUserSetWindowsHookEx
NtUserSetWindowsHookEx
NtUserSetWindowsHookAW
NtUserSetWindowsHookAW
NtUserSetProcessWindowStation
NtUserSetProcessWindowStation
NtUserSetKeyboardState
NtUserSetKeyboardState
NtUserSetImeHotKey
NtUserSetImeHotKey
NtUserSetConsoleReserveKeys
NtUserSetConsoleReserveKeys
NtUserRegisterHotKey
NtUserRegisterHotKey
NtUserOpenWindowStation
NtUserOpenWindowStation
NtUserMapVirtualKeyEx
NtUserMapVirtualKeyEx
NtUserLockWindowStation
NtUserLockWindowStation
NtUserLoadKeyboardLayoutEx
NtUserLoadKeyboardLayoutEx
NtUserGetProcessWindowStation
NtUserGetProcessWindowStation
NtUserGetKeyState
NtUserGetKeyState
NtUserGetKeyNameText
NtUserGetKeyNameText
NtUserGetKeyboardState
NtUserGetKeyboardState
NtUserGetKeyboardLayoutName
NtUserGetKeyboardLayoutName
NtUserGetKeyboardLayoutList
NtUserGetKeyboardLayoutList
NtUserGetImeHotKey
NtUserGetImeHotKey
NtUserGetCPD
NtUserGetCPD
NtUserGetAsyncKeyState
NtUserGetAsyncKeyState
NtUserCreateWindowStation
NtUserCreateWindowStation
NtUserCloseWindowStation
NtUserCloseWindowStation
NtUserCheckImeHotKey
NtUserCheckImeHotKey
NtUserCallMsgFilter
NtUserCallMsgFilter
NtUserAlterWindowStyle
NtUserAlterWindowStyle
NtUserActivateKeyboardLayout
NtUserActivateKeyboardLayout
NtGdiScaleViewportExtEx
NtGdiScaleViewportExtEx
NtGdiDvpWaitForVideoPortSync
NtGdiDvpWaitForVideoPortSync
NtGdiDvpUpdateVideoPort
NtGdiDvpUpdateVideoPort
NtGdiDvpGetVideoPortConnectInfo
NtGdiDvpGetVideoPortConnectInfo
NtGdiDvpGetVideoPortOutputFormats
NtGdiDvpGetVideoPortOutputFormats
NtGdiDvpGetVideoPortLine
NtGdiDvpGetVideoPortLine
NtGdiDvpGetVideoPortInputFormats
NtGdiDvpGetVideoPortInputFormats
NtGdiDvpGetVideoPortFlipStatus
NtGdiDvpGetVideoPortFlipStatus
NtGdiDvpGetVideoPortField
NtGdiDvpGetVideoPortField
NtGdiDvpGetVideoPortBandwidth
NtGdiDvpGetVideoPortBandwidth
NtGdiDvpFlipVideoPort
NtGdiDvpFlipVideoPort
NtGdiDvpDestroyVideoPort
NtGdiDvpDestroyVideoPort
NtGdiDvpCreateVideoPort
NtGdiDvpCreateVideoPort
NtGdiDvpCanCreateVideoPort
NtGdiDvpCanCreateVideoPort
NtGdiDdSetColorKey
NtGdiDdSetColorKey
read_shadow_sdt failed, error %d
read_shadow_sdt failed, error %d
check_win32k_sdt: cannot alloc %d bytes
check_win32k_sdt: cannot alloc %d bytes
Cannot read win32k_sdt at %p size %X, error %d
Cannot read win32k_sdt at %p size %X, error %d
win32k_sdt[%d] (%s) hooked, addr %p %s
win32k_sdt[%d] (%s) hooked, addr %p %s
win32k_sdt[%d] hooked, addr %p %s
win32k_sdt[%d] hooked, addr %p %s
GetNamedPipeServerProcessId
GetNamedPipeServerProcessId
read_kddb read %X bytes, error %d
read_kddb read %X bytes, error %d
cannot read MmNonPagedPoolStart (%p), error %d
cannot read MmNonPagedPoolStart (%p), error %d
cannot read MmNonPagedPoolEnd (%p), error %d
cannot read MmNonPagedPoolEnd (%p), error %d
cannot read MmPagedPoolStart (%p), error %d
cannot read MmPagedPoolStart (%p), error %d
cannot read MmPagedPoolEnd (%p), error %d
cannot read MmPagedPoolEnd (%p), error %d
cannot read KernelVerifier (%p), error %d
cannot read KernelVerifier (%p), error %d
WindowsType: %S
WindowsType: %S
ETHREAD.StartAddress %X
ETHREAD.StartAddress %X
KiProcessorBlock: %p (%X)
KiProcessorBlock: %p (%X)
KernelVerifier: %X
KernelVerifier: %X
KeBugCheckCallbackList: %p (%X)
KeBugCheckCallbackList: %p (%X)
WorkerRoutine: %p %s
WorkerRoutine: %p %s
IdleFunction: %p %s
IdleFunction: %p %s
IdleFunction: %p %s
IdleFunction: %p %s
KPRCB[%d].WorkerRoutine: %p %s
KPRCB[%d].WorkerRoutine: %p %s
KPRCB[%d].IdleFunction: %p %s
KPRCB[%d].IdleFunction: %p %s
KPRCB[%d].IdleFunction: %p %s
KPRCB[%d].IdleFunction: %p %s
read_kpcr return %X bytes, error %d, ntstatus %X
read_kpcr return %X bytes, error %d, ntstatus %X
read_kpcr return %X bytes, error %d
read_kpcr return %X bytes, error %d
KPCR[%d] %p major %X minor %X
KPCR[%d] %p major %X minor %X
KPCR[%d] %p
KPCR[%d] %p
get_os_info return %X bytes, error %d, ntstatus %X
get_os_info return %X bytes, error %d, ntstatus %X
get_os_info return %X bytes, error %d
get_os_info return %X bytes, error %d
NtMajorVersion: %d
NtMajorVersion: %d
NtMinorVersion: %d
NtMinorVersion: %d
BuildNumber: %d
BuildNumber: %d
GlobalFlag: %X
GlobalFlag: %X
Processors: %d
Processors: %d
MmVerifierFlags %d
MmVerifierFlags %d
MmSystemSize %d %s
MmSystemSize %d %s
DebuggerEnabled %d
DebuggerEnabled %d
DebuggerNotPresent %d
DebuggerNotPresent %d
SafeBootMode %d
SafeBootMode %d
NXSupportPolicy %X
NXSupportPolicy %X
CR0 %8.8X %s
CR0 %8.8X %s
CR4 %8.8X %s
CR4 %8.8X %s
Cannot open mailslot %S, error %d
Cannot open mailslot %S, error %d
get_mail_slot_owner(%S): returned %d bytes, error %d, ntstatus %X
get_mail_slot_owner(%S): returned %d bytes, error %d, ntstatus %X
get_mail_slot_owner(%S): returned %d bytes, error %d
get_mail_slot_owner(%S): returned %d bytes, error %d
Cannot open named pipe %S, error %d
Cannot open named pipe %S, error %d
GetNamedPipeServerProcessId(%S) failed, error %d
GetNamedPipeServerProcessId(%S) failed, error %d
get_named_pipe_owner(%S): returned %d bytes, error %d, ntstatus %X
get_named_pipe_owner(%S): returned %d bytes, error %d, ntstatus %X
get_named_pipe_owner(%S): returned %d bytes, error %d
get_named_pipe_owner(%S): returned %d bytes, error %d
read_lpc_port_chars: len %d, returned %d bytes, error %d, ntstatus %X
read_lpc_port_chars: len %d, returned %d bytes, error %d, ntstatus %X
read_lpc_port_chars: len %d, returned %d bytes, error %d
read_lpc_port_chars: len %d, returned %d bytes, error %d
read_unicode_string: len %d, returned %d bytes, error %d, ntstatus %X
read_unicode_string: len %d, returned %d bytes, error %d, ntstatus %X
read_unicode_string: len %d, returned %d bytes, error %d
read_unicode_string: len %d, returned %d bytes, error %d
read_drivers_list: cannot get size of drivers list, returned %d bytes, error %d, ntstatus %X
read_drivers_list: cannot get size of drivers list, returned %d bytes, error %d, ntstatus %X
read_drivers_list: cannot get size of drivers list, returned %d bytes, error %d
read_drivers_list: cannot get size of drivers list, returned %d bytes, error %d
read_drivers_list: cannot alloc %X bytes for driver list
read_drivers_list: cannot alloc %X bytes for driver list
read_drivers_list: cannot read drivers list, error %d, ntstatus %X
read_drivers_list: cannot read drivers list, error %d, ntstatus %X
read_drivers_list: cannot read drivers list, error %d
read_drivers_list: cannot read drivers list, error %d
%p:%X flags %X LoadCount %d %s
%p:%X flags %X LoadCount %d %s
read_KiThreadSelectNotifyRoutine failed, error %d
read_KiThreadSelectNotifyRoutine failed, error %d
read_KiSwapContextNotifyRoutine failed, error %d
read_KiSwapContextNotifyRoutine failed, error %d
read_KiTimeUpdateNotifyRoutine failed, error %d
read_KiTimeUpdateNotifyRoutine failed, error %d
read_PspLegoNotifyRoutine failed, error %d
read_PspLegoNotifyRoutine failed, error %d
read_KiDebugRoutine failed, error %d
read_KiDebugRoutine failed, error %d
read_msrs failed, error %d, ntstatus %X
read_msrs failed, error %d, ntstatus %X
read_msrs failed, error %d
read_msrs failed, error %d
IManageProcess: Cannot OpenProcess %d
IManageProcess: Cannot OpenProcess %d
IManageProcess: Cannot open process %d
IManageProcess: Cannot open process %d
read_win32_process for PID %X failed, error %d, status %X
read_win32_process for PID %X failed, error %d, status %X
read_win32_process for PID %X failed, error %d
read_win32_process for PID %X failed, error %d
read_dword(%p, PID %d) failed, error %d, ntstatus %X
read_dword(%p, PID %d) failed, error %d, ntstatus %X
read_dword(%p, PID %d) failed, error %d
read_dword(%p, PID %d) failed, error %d
read_ptr(%p, PID %d) failed, error %d, ntstatus %X
read_ptr(%p, PID %d) failed, error %d, ntstatus %X
read_ptr(%p, PID %d) failed, error %d
read_ptr(%p, PID %d) failed, error %d
rp_ReadProcessMemory(%p size %X) from %p error %d
rp_ReadProcessMemory(%p size %X) from %p error %d
read_token for PID %X failed, error %d, status %X
read_token for PID %X failed, error %d, status %X
read_token for PID %X failed, error %d
read_token for PID %X failed, error %d
open_proc(%d, access %X) failed, error %d, ntstatus %X
open_proc(%d, access %X) failed, error %d, ntstatus %X
open_proc(%d, access %X) failed, error %d
open_proc(%d, access %X) failed, error %d
rp_OpenProcess(%d, access %X) dwRet %d, error %d
rp_OpenProcess(%d, access %X) dwRet %d, error %d
rp_TerminateProcess(%p, %X) dwRet %d, error %d
rp_TerminateProcess(%p, %X) dwRet %d, error %d
Major %d Minor %d BuildNumber %d PlatformId %d ServicePackMajor %d ServicePackMinor %d SuiteMask %d ProductType %d CSDVersion %S
Major %d Minor %d BuildNumber %d PlatformId %d ServicePackMajor %d ServicePackMinor %d SuiteMask %d ProductType %d CSDVersion %S
ProductType: %X
ProductType: %X
Cannot open RPC control, error %X
Cannot open RPC control, error %X
msgsvcsend
msgsvcsend
_ILocalObjectExporter
_ILocalObjectExporter
IVsShell
IVsShell
IWbemLoginClientID
IWbemLoginClientID
ICertProtect
ICertProtect
_IBTFTPApiEvents
_IBTFTPApiEvents
_s_PasswordRecovery
_s_PasswordRecovery
wininet_UrlCache
wininet_UrlCache
_IObjectExporter
_IObjectExporter
WMsgAPIs
WMsgAPIs
WMsgKAPIs
WMsgKAPIs
INCryptKeyIso
INCryptKeyIso
HttpProxyMgrProvider
HttpProxyMgrProvider
IKeySvcR
IKeySvcR
WcnTransportRpc
WcnTransportRpc
IPortResolve
IPortResolve
IWbemLoginHelper
IWbemLoginHelper
LRpcSIDKey
LRpcSIDKey
ISmartCardRootCerts
ISmartCardRootCerts
IDebugPortSupplier2
IDebugPortSupplier2
IAsyncOperation
IAsyncOperation
IPipelineElement
IPipelineElement
OnlineProviderCertInterface
OnlineProviderCertInterface
IBackgroundCopyJobHttpOptions
IBackgroundCopyJobHttpOptions
HttpProxyMgrClient
HttpProxyMgrClient
IStaticPortMappingCollection
IStaticPortMappingCollection
IKeySvc
IKeySvc
s_WindowsShutdown
s_WindowsShutdown
IWebBrowser2
IWebBrowser2
IDebugPortSupplierLocale2
IDebugPortSupplierLocale2
IUPnPHttpHeaderControl
IUPnPHttpHeaderControl
WINHTTP_AUTOPROXY_SERVICE
WINHTTP_AUTOPROXY_SERVICE
IErcLuaSupport
IErcLuaSupport
IDebugPortSupplier3
IDebugPortSupplier3
IKeySvc2
IKeySvc2
BackupKey
BackupKey
IWerReport
IWerReport
ICertPassage
ICertPassage
IStaticPortMapping
IStaticPortMapping
IDebugPortSupplierEx2
IDebugPortSupplierEx2
IWbemLevel1Login
IWbemLevel1Login
IWebBrowserApp
IWebBrowserApp
msgsvc
msgsvc
IShellWindows
IShellWindows
RpcBindingFromStringBinding(%S) failed: %d
RpcBindingFromStringBinding(%S) failed: %d
RpcMgmtInqIfIds(%S) failed: %d
RpcMgmtInqIfIds(%S) failed: %d
RpcStringBindingCompose failed: %d
RpcStringBindingCompose failed: %d
RpcBindingFromStringBinding failed: %d
RpcBindingFromStringBinding failed: %d
RpcMgmtInqIfIds failed: %d
RpcMgmtInqIfIds failed: %d
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d : %s
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d : %s
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d : (%s)
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d : (%s)
RpcMgmtEpEltInqBegin failed: %d
RpcMgmtEpEltInqBegin failed: %d
Cannot read npc table, readed %X bytes
Cannot read npc table, readed %X bytes
rpcrt4
rpcrt4
%s.AddressChangeFn: %p %s
%s.AddressChangeFn: %p %s
rpcrt4_hack::check_myself: exception %d occured
rpcrt4_hack::check_myself: exception %d occured
rpcrt4_hack::try_hack: cannot find RpcServerRegisterIfEx
rpcrt4_hack::try_hack: cannot find RpcServerRegisterIfEx
I_RpcInitNdrImports
I_RpcInitNdrImports
load_driver(%S) returned %X
load_driver(%S) returned %X
Loaded kernel driver: %S
Loaded kernel driver: %S
Error loading kernel driver: %ls - 0xx
Error loading kernel driver: %ls - 0xx
Error loading kernel driver: %S - 0xx
Error loading kernel driver: %S - 0xx
Error loading kernel driver: %S - OpenSCManager 0xx
Error loading kernel driver: %S - OpenSCManager 0xx
tcpip
tcpip
ClientImmProcessKey
ClientImmProcessKey
fnHkOPTINLPEVENTMSG
fnHkOPTINLPEVENTMSG
fnHkINLPMSG
fnHkINLPMSG
fnSENTDDEMSG
fnSENTDDEMSG
fnDWORDOPTINLPMSG
fnDWORDOPTINLPMSG
RealMsgWaitForMultipleObjectsEx
RealMsgWaitForMultipleObjectsEx
PEB.KernelCallbackTable patched, %p
PEB.KernelCallbackTable patched, %p
user32_hack::try_hack: bad PE passed
user32_hack::try_hack: bad PE passed
user32_hack::try_hack: cannot read import table
user32_hack::try_hack: cannot read import table
pfnWowMsgBoxIndirectCallback
pfnWowMsgBoxIndirectCallback
Unknown apfnDispatch size: %d
Unknown apfnDispatch size: %d
%s_hack::try_hack: bad PE passed
%s_hack::try_hack: bad PE passed
%s_hack::try_hack: cannot read exports, error %d
%s_hack::try_hack: cannot read exports, error %d
%s_hack::try_hack: cannot find section .data
%s_hack::try_hack: cannot find section .data
%s_hack::try_hack: cannot read section .data
%s_hack::try_hack: cannot read section .data
%s_hack::try_hack: cannot read section .rdata
%s_hack::try_hack: cannot read section .rdata
%s_hack::try_hack: cannot find section .text
%s_hack::try_hack: cannot find section .text
%s_hack::try_hack: cannot read section .text
%s_hack::try_hack: cannot read section .text
DxgkReleaseKeyedMutex2
DxgkReleaseKeyedMutex2
DxgkAcquireKeyedMutex2
DxgkAcquireKeyedMutex2
DxgkOpenKeyedMutex2
DxgkOpenKeyedMutex2
DxgkCreateKeyedMutex2
DxgkCreateKeyedMutex2
DxgkReleaseKeyedMutex
DxgkReleaseKeyedMutex
DxgkAcquireKeyedMutex
DxgkAcquireKeyedMutex
DxgkDestroyKeyedMutex
DxgkDestroyKeyedMutex
DxgkOpenKeyedMutex
DxgkOpenKeyedMutex
DxgkCreateKeyedMutex
DxgkCreateKeyedMutex
Cannot read gDxgkInterface, readed %X bytes
Cannot read gDxgkInterface, readed %X bytes
WindowHasShadow
WindowHasShadow
DisableProcessWindowsGhosting
DisableProcessWindowsGhosting
zzzUnhookWindowsHook
zzzUnhookWindowsHook
xxxUpdateWindows
xxxUpdateWindows
xxxArrangeIconicWindows
xxxArrangeIconicWindows
SetWindowState
SetWindowState
ClearWindowState
ClearWindowState
SetMsgBox
SetMsgBox
GetKeyboardType
GetKeyboardType
GetKeyboardLayout
GetKeyboardLayout
RemotePassthruDisable
RemotePassthruDisable
xxxRemotePassthruEnable
xxxRemotePassthruEnable
Cannot read gpsi, readed %X bytes
Cannot read gpsi, readed %X bytes
Cannot read gpsi handlers, readed %X bytes
Cannot read gpsi handlers, readed %X bytes
Cannot read apfnSimpleCall, readed %X bytes
Cannot read apfnSimpleCall, readed %X bytes
Cannot read gapfnMessageCall, readed %X bytes
Cannot read gapfnMessageCall, readed %X bytes
Cannot read gapfnScSendMessage, readed %X bytes
Cannot read gapfnScSendMessage, readed %X bytes
Cannot read gaNewProcAddresses, readed %X bytes
Cannot read gaNewProcAddresses, readed %X bytes
Cannot open logfile %S
Cannot open logfile %S
Cannot create stop event, error %d
Cannot create stop event, error %d
Driver %S loaded from %S
Driver %S loaded from %S
SrvGetConsoleKeyboardLayoutName
SrvGetConsoleKeyboardLayoutName
SrvSetConsoleKeyShortcuts
SrvSetConsoleKeyShortcuts
SrvGetConsoleAliasExes
SrvGetConsoleAliasExes
SrvGetConsoleAliasExesLength
SrvGetConsoleAliasExesLength
SrvVDMConsoleOperation
SrvVDMConsoleOperation
SrvGetLargestConsoleWindowSize
SrvGetLargestConsoleWindowSize
SrvExitWindowsEx
SrvExitWindowsEx
winsrv.dll
winsrv.dll
Unknown size of ConsoleServerApiDispatchTable: %d
Unknown size of ConsoleServerApiDispatchTable: %d
Unknown size of UserServerApiDispatchTable: %d
Unknown size of UserServerApiDispatchTable: %d
CallUserpExitWindowsEx
CallUserpExitWindowsEx
GetConsoleAliasExesInternal
GetConsoleAliasExesInternal
GetConsoleAliasExesLengthInternal
GetConsoleAliasExesLengthInternal
SetConsoleKeyShortcuts
SetConsoleKeyShortcuts
GetConsoleKeyboardLayoutNameWorker
GetConsoleKeyboardLayoutNameWorker
SetConsoleOutputCPInternal
SetConsoleOutputCPInternal
GetConsoleOutputCP
GetConsoleOutputCP
GetLargestConsoleWindowSize
GetLargestConsoleWindowSize
reg_ccs_services::read failed - error %d
reg_ccs_services::read failed - error %d
Cannot open key %S, error %d
Cannot open key %S, error %d
SafeSecondaryLog(%d) failed, error %d
SafeSecondaryLog(%d) failed, error %d
SafeSecondaryLog failed, error %d
SafeSecondaryLog failed, error %d
SafeSendLog(%d) failed, error %d
SafeSendLog(%d) failed, error %d
SafeSendLog failed, error %d
SafeSendLog failed, error %d
Bad memory %p len %X in dump_hex_buffer
Bad memory %p len %X in dump_hex_buffer
Cannot alloc %d bytes for delayed imports
Cannot alloc %d bytes for delayed imports
Cannot alloc %d bytes for imports
Cannot alloc %d bytes for imports
read_import_safe(%s) failed %X
read_import_safe(%s) failed %X
Cannot realloc %d bytes for iat
Cannot realloc %d bytes for iat
read_delayed_safe(%s) failed %X
read_delayed_safe(%s) failed %X
store2md_cache: cannot alloc %d bytes
store2md_cache: cannot alloc %d bytes
store2md_cache: cannot realloc, alloced %d bytes
store2md_cache: cannot realloc, alloced %d bytes
wdigest.dll
wdigest.dll
tspkg.dll
tspkg.dll
schannel.dll
schannel.dll
pku2u.dll
pku2u.dll
negoexts.dll
negoexts.dll
msv1_0.dll
msv1_0.dll
livessp.dll
livessp.dll
kerberos.dll
kerberos.dll
umpnpmgr.dll
umpnpmgr.dll
combase.dll
combase.dll
ntdsa.dll
ntdsa.dll
ntdll.dll
ntdll.dll
cryptbase.dll
cryptbase.dll
ncrypt.dll
ncrypt.dll
rpcrt4.dll
rpcrt4.dll
imm32.dll
imm32.dll
user32.dll
user32.dll
kernelbase.dll
kernelbase.dll
kernel32.dll
kernel32.dll
advapi32.dll
advapi32.dll
ole32.dll
ole32.dll
Cannot alloc %X bytes for relocs
Cannot alloc %X bytes for relocs
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired
WS2_32.dll
WS2_32.dll
RPCRT4.dll
RPCRT4.dll
GetProcessHeap
GetProcessHeap
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegOpenKeyExA
RegOpenKeyExA
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
GetWindowsDirectoryW
GetWindowsDirectoryW
GetCPInfo
GetCPInfo
RegQueryInfoKeyW
RegQueryInfoKeyW
RegEnumKeyW
RegEnumKeyW
zcÃ
zcÃ
.?AVMyWindowsChecker@@
.?AVMyWindowsChecker@@
.?AV?$rpcrt4_hack@U_IMAGE_NT_HEADERS@@@@
.?AV?$rpcrt4_hack@U_IMAGE_NT_HEADERS@@@@
.?AVtcpip_hack@@
.?AVtcpip_hack@@
.?AV?$import_holder@U_IMAGE_NT_HEADERS@@@CMN@@
.?AV?$import_holder@U_IMAGE_NT_HEADERS@@@CMN@@
.?AVinmem_import_holder@CMN@@
.?AVinmem_import_holder@CMN@@
.?AVimport_holder_intf@CMN@@
.?AVimport_holder_intf@CMN@@
.?AVmodule_import@CMN@@
.?AVmodule_import@CMN@@
aR.Rn
aR.Rn
X.UJ^A
X.UJ^A
w%xyW
w%xyW
f.Gkf
f.Gkf
%0X0m0
%0X0m0
>$?(?,?0?
>$?(?,?0?
3&4;456?90:
3&4;456?90:
77g7
77g7
7>7[7`7|7
7>7[7`7|7
6#8*878^8~8
6#8*878^8~8
11_1
11_1
0#101#202
0#101#202
0 11h1J3
0 11h1J3
6%7S7
6%7S7
7*717>7[8
7*717>7[8
=!>&>9>>>
=!>&>9>>>
7&7@7l7Â8N8V8z8
7&7@7l7Â8N8V8z8
:);4;>;\;
:);4;>;\;
0%0X0
0%0X0
= >$>(>,>0>
= >$>(>,>0>
?,?4?\?|?
?,?4?\?|?
.----/01/01/01
.----/01/01/01
KERNEL32.DLL
KERNEL32.DLL
mscoree.dll
mscoree.dll
U%SystemRoot%\system32\svchost.exe
U%SystemRoot%\system32\svchost.exe
%SystemRoot%\system32\svchost
%SystemRoot%\system32\svchost
WSOCKTRANSPORT
WSOCKTRANSPORT
TCPIP6
TCPIP6
TCPIP
TCPIP
STORPORT
STORPORT
STORMINIPORT
STORMINIPORT
SOFTPCI
SOFTPCI
SCSIPORT
SCSIPORT
SCSIMINIPORT
SCSIMINIPORT
SBP2PORT
SBP2PORT
FCPORT
FCPORT
PassiveWatchdogTimeout
PassiveWatchdogTimeout
sImageExecutionOptions
sImageExecutionOptions
ErrorPortStartTimeout
ErrorPortStartTimeout
ErrorPortCommTimeout
ErrorPortCommTimeout
DisablePagingExecutive
DisablePagingExecutive
DebuggerMaxModuleMsgs
DebuggerMaxModuleMsgs
CountOperations
CountOperations
B\\.\
B\\.\
Psapi.dll
Psapi.dll
sWindows PowerShell
sWindows PowerShell
tHost Process for Windows Tasks
tHost Process for Windows Tasks
Windows Problem Reporting 32 bit
Windows Problem Reporting 32 bit
Windows Problem Reporting
Windows Problem Reporting
Windows Modules Installer
Windows Modules Installer
mWindows Start-Up Application
mWindows Start-Up Application
tWindows Search Indexer
tWindows Search Indexer
sWindows Server Initial Configuration Tasks
sWindows Server Initial Configuration Tasks
Windows Media Player
Windows Media Player
Dump Reporting Tool
Dump Reporting Tool
Error Reporter
Error Reporter
rWindows Control Panel 32 bit
rWindows Control Panel 32 bit
Windows Control Panel
Windows Control Panel
Windows Connect Now - Config Registrar Service
Windows Connect Now - Config Registrar Service
Windows Media Player Network Sharing Service
Windows Media Player Network Sharing Service
Windows firewall
Windows firewall
Windows Error Reporting Service
Windows Error Reporting Service
tWindows Defender
tWindows Defender
vError reporting service
vError reporting service
eWindows update service
eWindows update service
Windows Image Acquisition
Windows Image Acquisition
WebClient
WebClient
tWindows Security Center Notification App
tWindows Security Center Notification App
yWindows Based Script Host
yWindows Based Script Host
Windows installer 32 bit
Windows installer 32 bit
Windows installer
Windows installer
Windows 16-bit Virtual Machine
Windows 16-bit Virtual Machine
Windows Management Instrumentation
Windows Management Instrumentation
Windows User Mode Driver Manager
Windows User Mode Driver Manager
MS tftp
MS tftp
MS ftp 32 bit
MS ftp 32 bit
MS ftp
MS ftp
Microsoft Help and Support Center
Microsoft Help and Support Center
Cmd.exe 32 bit
Cmd.exe 32 bit
Cmd.exe
Cmd.exe
Windows Logon User Interface Host
Windows Logon User Interface Host
Windows update
Windows update
tGoogle Chrome
tGoogle Chrome
rOpera Internet Browser
rOpera Internet Browser
Mozilla Thunderbird Mail and News Client
Mozilla Thunderbird Mail and News Client
dFirefox browser
dFirefox browser
Services.exe
Services.exe
%SystemRoot%\msagent\agentsvr.exe
%SystemRoot%\msagent\agentsvr.exe
%SystemRoot%\System32\dfrgfat.exe
%SystemRoot%\System32\dfrgfat.exe
%SystemRoot%\System32\dfrgntfs.exe
%SystemRoot%\System32\dfrgntfs.exe
%SystemRoot%\System32\services.exe
%SystemRoot%\System32\services.exe
%SystemRoot%\System32\svchost.exe
%SystemRoot%\System32\svchost.exe
%SystemRoot%\System32\alg.exe
%SystemRoot%\System32\alg.exe
%SystemRoot%\System32\spoolsv.exe
%SystemRoot%\System32\spoolsv.exe
%SystemRoot%\System32\net.exe
%SystemRoot%\System32\net.exe
%SystemRoot%\System32\net1.exe
%SystemRoot%\System32\net1.exe
%SystemRoot%\System32\cmd.exe
%SystemRoot%\System32\cmd.exe
%SystemRoot%\System32\notepad.exe
%SystemRoot%\System32\notepad.exe
%SystemRoot%\System32\calc.exe
%SystemRoot%\System32\calc.exe
%SystemRoot%\System32\PTF.exe
%SystemRoot%\System32\PTF.exe
%SystemRoot%\System32\tPTF.exe
%SystemRoot%\System32\tPTF.exe
%SystemRoot%\System32\telnet.exe
%SystemRoot%\System32\telnet.exe
%SystemRoot%\System32\taskkill.exe
%SystemRoot%\System32\taskkill.exe
%SystemRoot%\System32\ctfmon.exe
%SystemRoot%\System32\ctfmon.exe
%SystemRoot%\System32\wdfmgr.exe
%SystemRoot%\System32\wdfmgr.exe
%SystemRoot%\System32\mmc.exe
%SystemRoot%\System32\mmc.exe
%SystemRoot%\System32\userinit.exe
%SystemRoot%\System32\userinit.exe
%SystemRoot%\System32\wbem\wmiprvse.exe
%SystemRoot%\System32\wbem\wmiprvse.exe
%SystemRoot%\System32\wbem\wmiadap.exe
%SystemRoot%\System32\wbem\wmiadap.exe
%SystemRoot%\explorer.exe
%SystemRoot%\explorer.exe
%SystemRoot%\System32\lsass.exe
%SystemRoot%\System32\lsass.exe
%SystemRoot%\System32\winlogon.exe
%SystemRoot%\System32\winlogon.exe
%SystemRoot%\System32\LogonUI.exe
%SystemRoot%\System32\LogonUI.exe
%SystemRoot%\System32\wuauclt.exe
%SystemRoot%\System32\wuauclt.exe
%SystemRoot%\System32\wuauclt1.exe
%SystemRoot%\System32\wuauclt1.exe
%SystemRoot%\System32\CCM\CcmExec.exe
%SystemRoot%\System32\CCM\CcmExec.exe
%SystemRoot%\System32\csrss.exe
%SystemRoot%\System32\csrss.exe
%SystemRoot%\System32\smss.exe
%SystemRoot%\System32\smss.exe
\SystemRoot\System32\smss.exe
\SystemRoot\System32\smss.exe
%SystemRoot%\System32\inetsrv\w3wp.exe
%SystemRoot%\System32\inetsrv\w3wp.exe
%SystemRoot%\System32\schtasks.exe
%SystemRoot%\System32\schtasks.exe
%SystemRoot%\System32\tstheme.exe
%SystemRoot%\System32\tstheme.exe
%SystemRoot%\System32\control.exe
%SystemRoot%\System32\control.exe
%SystemRoot%\System32\taskmgr.exe
%SystemRoot%\System32\taskmgr.exe
%SystemRoot%\System32\dwwin.exe
%SystemRoot%\System32\dwwin.exe
%SystemRoot%\System32\drwtsn32.exe
%SystemRoot%\System32\drwtsn32.exe
%SystemRoot%\System32\dumprep.exe
%SystemRoot%\System32\dumprep.exe
%SystemRoot%\System32\dfssvc.exe
%SystemRoot%\System32\dfssvc.exe
%SystemRoot%\System32\dllhost.exe
%SystemRoot%\System32\dllhost.exe
%SystemRoot%\System32\ntvdm.exe
%SystemRoot%\System32\ntvdm.exe
%SystemRoot%\System32\rundll32.exe
%SystemRoot%\System32\rundll32.exe
%SystemRoot%\System32\msiexec.exe
%SystemRoot%\System32\msiexec.exe
%SystemRoot%\System32\mshta.exe
%SystemRoot%\System32\mshta.exe
%SystemRoot%\System32\regsvr32.exe
%SystemRoot%\System32\regsvr32.exe
%SystemRoot%\System32\cscript.exe
%SystemRoot%\System32\cscript.exe
%SystemRoot%\System32\wscript.exe
%SystemRoot%\System32\wscript.exe
%SystemRoot%\System32\wscntfy.exe
%SystemRoot%\System32\wscntfy.exe
%SystemRoot%\System32\mstsc.exe
%SystemRoot%\System32\mstsc.exe
%SystemRoot%\System32\dashost.exe
%SystemRoot%\System32\dashost.exe
far.exe
far.exe
Far.exe
Far.exe
CLSID\{FC7D9E02-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32
CLSID\{FC7D9E02-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32
CLSID\{73FDDC80-AEA9-101A-98A7-00AA00374959}\LocalServer32
CLSID\{73FDDC80-AEA9-101A-98A7-00AA00374959}\LocalServer32
CLSID\{0002DF01-0000-0000-C000-000000000046}\LocalServer32
CLSID\{0002DF01-0000-0000-C000-000000000046}\LocalServer32
iedw.exe
iedw.exe
%SystemRoot%\System32\oobechk.exe
%SystemRoot%\System32\oobechk.exe
%SystemRoot%\System32\oobe.exe
%SystemRoot%\System32\oobe.exe
%SystemRoot%\System32\psxss.exe
%SystemRoot%\System32\psxss.exe
%SystemRoot%\System32\internat.exe
%SystemRoot%\System32\internat.exe
AcroRd32.exe
AcroRd32.exe
excel.exe
excel.exe
outlook.exe
outlook.exe
winword.exe
winword.exe
powerpnt.exe
powerpnt.exe
wmplayer.exe
wmplayer.exe
firefox.exe
firefox.exe
thunderbird.exe
thunderbird.exe
Opera.exe
Opera.exe
WinRAR.exe
WinRAR.exe
%SystemRoot%\System32\wininit.exe
%SystemRoot%\System32\wininit.exe
%SystemRoot%\System32\lsm.exe
%SystemRoot%\System32\lsm.exe
%SystemRoot%\System32\dwm.exe
%SystemRoot%\System32\dwm.exe
%SystemRoot%\System32\werfault.exe
%SystemRoot%\System32\werfault.exe
%SystemRoot%\System32\taskeng.exe
%SystemRoot%\System32\taskeng.exe
%SystemRoot%\System32\conime.exe
%SystemRoot%\System32\conime.exe
%SystemRoot%\System32\wudfhost.exe
%SystemRoot%\System32\wudfhost.exe
%SystemRoot%\System32\taskhost.exe
%SystemRoot%\System32\taskhost.exe
%SystemRoot%\System32\conhost.exe
%SystemRoot%\System32\conhost.exe
%SystemRoot%\System32\rdpclip.exe
%SystemRoot%\System32\rdpclip.exe
%SystemRoot%\System32\SearchFilterHost.exe
%SystemRoot%\System32\SearchFilterHost.exe
%SystemRoot%\System32\SearchProtocolHost.exe
%SystemRoot%\System32\SearchProtocolHost.exe
csrss.exe
csrss.exe
svchost.exe
svchost.exe
alg.exe
alg.exe
sPptpMiniport
sPptpMiniport
Tcpip
Tcpip
psapi.dll
psapi.dll
127.0.0.1
127.0.0.1
\\.\pipe\
\\.\pipe\
\\.\mailslot\
\\.\mailslot\
SOFTWARE\Microsoft\Windows NT\CurrentVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion
\\.\Pipe\
\\.\Pipe\
\\.\Mailslot\
\\.\Mailslot\
ncacn_ip_tcp:
ncacn_ip_tcp:
ncadg_ip_udp:
ncadg_ip_udp:
\\pipe\\
\\pipe\\
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell
SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell
RemediationExe
RemediationExe
SOFTWARE\Classes\SCCM.VAppLauncher\shell\Open\command
SOFTWARE\Classes\SCCM.VAppLauncher\shell\Open\command
SOFTWARE\Classes\CLSID\{00AAB372-0D6D-4976-B5F5-9BC7605E30BB}\LocalServer32
SOFTWARE\Classes\CLSID\{00AAB372-0D6D-4976-B5F5-9BC7605E30BB}\LocalServer32
SOFTWARE\Classes\CLSID\{3C296D07-90AE-4FAC-86F9-65EAA8B82D22}\LocalServer32
SOFTWARE\Classes\CLSID\{3C296D07-90AE-4FAC-86F9-65EAA8B82D22}\LocalServer32
SOFTWARE\Classes\CLSID\{D63B10C5-BB46-4990-A94F-E40B9D520160}\LocalServer32
SOFTWARE\Classes\CLSID\{D63B10C5-BB46-4990-A94F-E40B9D520160}\LocalServer32
SOFTWARE\Classes\CLSID\{03e64e17-b220-4052-9b9b-155f9cb8e016}\LocalServer32
SOFTWARE\Classes\CLSID\{03e64e17-b220-4052-9b9b-155f9cb8e016}\LocalServer32
SOFTWARE\Classes\CLSID\{1F69F884-285E-418E-9715-B9EEE402DD5F}\LocalServer32
SOFTWARE\Classes\CLSID\{1F69F884-285E-418E-9715-B9EEE402DD5F}\LocalServer32
Software\Microsoft\Windows\CurrentVersion\WINEVT\publishers
Software\Microsoft\Windows\CurrentVersion\WINEVT\publishers
Windows checker
Windows checker
1.0.0.3432
1.0.0.3432
wincheck.exe
wincheck.exe
0, 0, 8, 16
0, 0, 8, 16
fGAwoYMM.exe_1072_rwx_05990000_00001000:
.text
.text
.rdata
.rdata
@.data
@.data
fGAwoYMM.exe_1072_rwx_06230000_00004000:
Web Client Network
Web Client Network
Microsoft Windows Network
Microsoft Windows Network
fGAwoYMM.exe_1072_rwx_06260000_00004000:
Microsoft Windows Network
Microsoft Windows Network
fGAwoYMM.exe_1072_rwx_06280000_00004000:
Microsoft Windows Network
Microsoft Windows Network
NesIMIQs.exe_500_rwx_00401000_000EA000:
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
Microsoft Windows
Microsoft Windows
?!%C"
?!%C"
%uNaO
%uNaO
.YtUO
.YtUO
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
NesIMIQs.exe_500_rwx_009A0000_00001000:
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp
NesIMIQs.exe_500_rwx_00A00000_00001000:
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM
NesIMIQs.exe_500_rwx_00A10000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs
NesIMIQs.exe_500_rwx_00A30000_000E9000:
C{?%f{[
C{?%f{[
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
4%UMv
4%UMv
4%UEInb
4%UEInb
%uNaO
%uNaO
.YtUO
.YtUO
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
NesIMIQs.exe_500_rwx_00E20000_00001000:
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.inf
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.inf
NesIMIQs.exe_500_rwx_00E30000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.inf
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.inf
NesIMIQs.exe_500_rwx_00E40000_00001000:
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe
%Documents and Settings%\%current user%\dUskcAww\fGAwoYMM.exe
NesIMIQs.exe_500_rwx_00E50000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe
NesIMIQs.exe_500_rwx_00E80000_00001000:
fGAwoYMM.exe
fGAwoYMM.exe
NesIMIQs.exe_500_rwx_00E90000_00001000:
NesIMIQs.exe
NesIMIQs.exe
NesIMIQs.exe_500_rwx_00EA0000_00001000:
taskkill /FI "USERNAME eq adm" /F /IM fGAwoYMM.exe
taskkill /FI "USERNAME eq adm" /F /IM fGAwoYMM.exe
NesIMIQs.exe_500_rwx_00EB0000_00001000:
taskkill /FI "USERNAME eq adm" /F /IM NesIMIQs.exe
taskkill /FI "USERNAME eq adm" /F /IM NesIMIQs.exe
NesIMIQs.exe_500_rwx_00EC0000_00001000:
%Documents and Settings%\All Users\JuwEIgUE\reIEcoQI.exe
%Documents and Settings%\All Users\JuwEIgUE\reIEcoQI.exe
NesIMIQs.exe_500_rwx_00ED0000_00001000:
%Documents and Settings%\All Users\KAAo.txt
%Documents and Settings%\All Users\KAAo.txt
NesIMIQs.exe_500_rwx_00EE0000_00001000:
notepad.exe "%Documents and Settings%\All Users\KAAo.txt"
notepad.exe "%Documents and Settings%\All Users\KAAo.txt"
NesIMIQs.exe_500_rwx_00EF0000_00001000:
%Documents and Settings%\All Users\JuwEIgUE
%Documents and Settings%\All Users\JuwEIgUE
reIEcoQI.exe_1552_rwx_00401000_000EA000:
C{?%f{[
C{?%f{[
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
4%UMv
4%UMv
4%UEInb
4%UEInb
2software\microsoft\windows\currentversion\run
2software\microsoft\windows\currentversion\run
%uNaO
%uNaO
.YtUO
.YtUO
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
reIEcoQI.exe_1552_rwx_00720000_00001000:
%WinDir%\TEMP
%WinDir%\TEMP
reIEcoQI.exe_1552_rwx_00780000_00001000:
%Documents and Settings%\LocalService\dUskcAww\fGAwoYMM
%Documents and Settings%\LocalService\dUskcAww\fGAwoYMM
reIEcoQI.exe_1552_rwx_00790000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs
reIEcoQI.exe_1552_rwx_007B0000_000E9000:
C{?%f{[
C{?%f{[
7.qU6
7.qU6
TNcMdI
TNcMdI
vND.LOrg
vND.LOrg
.eH^\
.eH^\
w|.LV
w|.LV
QfC%d
QfC%d
dW0WaZ@%di
dW0WaZ@%di
O%%Sg
O%%Sg
[%dZr
[%dZr
l}9fT{
l}9fT{
E!.Lg:
E!.Lg:
\D.vY
\D.vY
m.TpM
m.TpM
.WYky?
.WYky?
?%sn6
?%sn6
.wbK3
.wbK3
Am%foEW
Am%foEW
%d[k#
%d[k#
k[w[.dx
k[w[.dx
Ho%sd^
Ho%sd^
.pgVM
.pgVM
.XU\:
.XU\:
.TU:67Y[
.TU:67Y[
mre%s
mre%s
Rx.AF{-F
Rx.AF{-F
.dA}R
.dA}R
9zE46}GF{-A}d8
9zE46}GF{-A}d8
Rx.AMb
Rx.AMb
Rx.AJ
Rx.AJ
Vy-A}y1
Vy-A}y1
]~]{:&]{>
]~]{:&]{>
Mr.0M8.wM
Mr.0M8.wM
F@%uF
F@%uF
5@.FJ
5@.FJ
r|M-
r|M-
9Q2.QD
9Q2.QD
s]{>EkAC.AZ?
s]{>EkAC.AZ?
]mYS_;-h}_/
]mYS_;-h}_/
%s>Ab
%s>Ab
GcMd
GcMd
7FZZZZ%
7FZZZZ%
&aTF{-A}d8
&aTF{-A}d8
Rx.AZu`\Vb)
Rx.AZu`\Vb)
Rx.AN~2
Rx.AN~2
Rx.AF z
Rx.AF z
x.ASs)
x.ASs)
Rx.AF{-6s z
Rx.AF{-6s z
]sc.Pu
]sc.Pu
).KQ>6V
).KQ>6V
yT%FZ
yT%FZ
d?%x1
d?%x1
u2S.cp
u2S.cp
~%m"%U
~%m"%U
R.BFX7
R.BFX7
.Cd"w
.Cd"w
/1:,*-.1
/1:,*-.1
#k%U,
#k%U,
:EW.yY
:EW.yY
%cMV=
%cMV=
hC%x}7
hC%x}7
.Gl^z
.Gl^z
>fAd:%U
>fAd:%U
.cW a
.cW a
]{.iA8
]{.iA8
8=d0,.eJ
8=d0,.eJ
KV.eb
KV.eb
.CYf?a8
.CYf?a8
=Btcp
=Btcp
x.sd6
x.sd6
4%UMv
4%UMv
4%UEInb
4%UEInb
%uNaO
%uNaO
.YtUO
.YtUO
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
Microsoft Windows eine Wiederherstellung in einem Moment beginnen.
.klicken, um zu kopieren
.klicken, um zu kopieren
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
Strafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich besch
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
ffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1
.Machen BitCoin Zahlung:2
.Machen BitCoin Zahlung:2
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5
DKlicken Sie auf "Import / Export".6
DKlicken Sie auf "Import / Export".6
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.7
8Klicken Sie auf "Sweep Key".9
8Klicken Sie auf "Sweep Key".9
.Internationale Anbieter=
.Internationale Anbieter=
WebbrowserD
WebbrowserD
&de.bitcoin.it/wiki/G
&de.bitcoin.it/wiki/G
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
Kennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f
~Microsoft Windows will begin a restoration process in a moment.
~Microsoft Windows will begin a restoration process in a moment.
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Operation Global 3 is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,
Enter your e-mail address(optional) and password. Make sure your password is secure.-
Enter your e-mail address(optional) and password. Make sure your password is secure.-
zSave your password safely, preferably offline(click Notepad)..
zSave your password safely, preferably offline(click Notepad)..
Follow the steps prompted on the website and pay close attention to the security recommendations.1
Follow the steps prompted on the website and pay close attention to the security recommendations.1
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
tLogin to your Bitcoin wallet blockchain.info/wallet/login 5
4Click on Import / Export. 6
4Click on Import / Export. 6
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7
$Click 'Sweep Key'.9
$Click 'Sweep Key'.9
.International Exchanges=
.International Exchanges=
&en.bitcoin.it/wiki/G
&en.bitcoin.it/wiki/G
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
Know the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.J
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)
Microsoft Windows inizier
Microsoft Windows inizier
Importo:
Importo:
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo
\Registrazione di un nuovo portafoglio BitCoin:
\Registrazione di un nuovo portafoglio BitCoin:
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo password
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Salvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.7
2Fare clic su 'Sweep Key'.9
2Fare clic su 'Sweep Key'.9
&it.bitcoin.it/wiki/G
&it.bitcoin.it/wiki/G
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Conoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.J
Microsoft Windows se iniciar
Microsoft Windows se iniciar
Fine Importe:
Fine Importe:
n de Windows sin posibilidad de recuperaci
n de Windows sin posibilidad de recuperaci
Operaci
Operaci
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
n: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,
gina web y prestar mucha atenci
gina web y prestar mucha atenci
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
pAcceda a su cartera blockchain.info/wallet/login Bitcoin5
FHaga clic en "Importar / Exportar".6
FHaga clic en "Importar / Exportar".6
sculas) y haga clic en" Add Private Key ".7
sculas) y haga clic en" Add Private Key ".7
2Haga clic en 'Sweep Key'.9
2Haga clic en 'Sweep Key'.9
Navegador WebD
Navegador WebD
&es.bitcoin.it/wiki/G
&es.bitcoin.it/wiki/G
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
n de copyright. Visita copyright.gov/help/faq/faq-infringement.html para m
reIEcoQI.exe_1552_rwx_00BA0000_00001000:
%Documents and Settings%\LocalService\dUskcAww\fGAwoYMM.inf
%Documents and Settings%\LocalService\dUskcAww\fGAwoYMM.inf
reIEcoQI.exe_1552_rwx_00BB0000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.inf
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.inf
reIEcoQI.exe_1552_rwx_00BC0000_00001000:
%Documents and Settings%\LocalService\dUskcAww\fGAwoYMM.exe
%Documents and Settings%\LocalService\dUskcAww\fGAwoYMM.exe
reIEcoQI.exe_1552_rwx_00BD0000_00001000:
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe
%Documents and Settings%\All Users\hcYYccwo\NesIMIQs.exe
reIEcoQI.exe_1552_rwx_00C00000_00001000:
fGAwoYMM.exe
fGAwoYMM.exe
reIEcoQI.exe_1552_rwx_00C10000_00001000:
NesIMIQs.exe
NesIMIQs.exe
reIEcoQI.exe_1552_rwx_00C20000_00001000:
taskkill /FI "USERNAME eq SYSTEM" /F /IM fGAwoYMM.exe
taskkill /FI "USERNAME eq SYSTEM" /F /IM fGAwoYMM.exe
reIEcoQI.exe_1552_rwx_00C30000_00001000:
taskkill /FI "USERNAME eq SYSTEM" /F /IM NesIMIQs.exe
taskkill /FI "USERNAME eq SYSTEM" /F /IM NesIMIQs.exe