Sei sulla pagina 1di 70

[

0:07b0] :LAUNCHER: START


[
0:07b0] :LAUNCHER: real entry point 0x4cce80, module base 0x400000
[
0:07b0] :LAUNCHER: Running on WindowsXP Service Pack 3
[
0:07b0] :LAUNCHER: VERSION 2.5.13.2201 PRO
[
0:07b0] :BOXMAN: Initializing...
[
0:07b0] :BOXMAN: Executable: TRAINER V4.EXE 'C:\DOCUMENTS AND SETTINGS\CAB
INA9\MIS DOCUMENTOS\DOWNLOADS\TRAINER V4\TRAINER V4.EXE'
[
0:07b0] :BOXMAN: Loading package C:\DOCUMENTS AND SETTINGS\CABINA9\MIS DOC
UMENTOS\DOWNLOADS\TRAINER V4\TRAINER V4.EXE
[
0:07b0] :BOXMAN: *SELFEXECUTABLE* 0x0006df60:05702719:0x33:'TRAINER V4.EXE
'
[
1:07b0] :BOXMAN: Content (0 items) verified
[
1:07b0] :BOXMAN: Package C:\DOCUMENTS AND SETTINGS\CABINA9\MIS DOCUMENTOS\
DOWNLOADS\TRAINER V4\TRAINER V4.EXE loaded successful
[
1:07b0] :BOXMAN: packages pattern defined as ''
[
1:07b0] :BOX/CATALOG: TRAINER V4.EXE (C:\DOCUMENTS AND SETTINGS\CABINA9\MI
S DOCUMENTOS\DOWNLOADS\TRAINER V4\TRAINER V4.EXE)
[
1:07b0] :BOXMAN: Initialized successful
[
1:07b0] :WRAPPER: initialize wrappers
[
1:07b0] :WRAPPER:
kernel32.dll
SetUnhandledExceptionFilter = 0x7c
8449fd/0x004f9150
[
1:07b0] :WRAPPER:
kernel32.dll
CreateFileA = 0x7c
801a28/0x004fa930
[
1:07b0] :WRAPPER:
kernel32.dll
CreateFileW = 0x7c
8107f0/0x004fa990
[
1:07b0] :WRAPPER:
kernel32.dll
GetFileAttributesA = 0x7c
8115cc/0x004f9f00
[
1:07b0] :WRAPPER:
kernel32.dll
GetFileAttributesW = 0x7c
80b7dc/0x004f9f40
[
1:07b0] :WRAPPER:
kernel32.dll
ReadFile = 0x7c
801812/0x004faac0
[
1:07b0] :WRAPPER:
kernel32.dll
CloseHandle = 0x7c
809bd7/0x004faa90
[
1:07b0] :WRAPPER:
kernel32.dll
SetFilePointer = 0x7c
810c1e/0x004fab40
[
1:07b0] :WRAPPER:
kernel32.dll
GetFileSize = 0x7c
810b07/0x004fa030
[
1:07b0] :WRAPPER:
kernel32.dll
ExitProcess = 0x7c
81cafa/0x004f9600
[
1:07b0] :WRAPPER:
kernel32.dll
CreateFileMappingA = 0x7c
8094ee/0x004fab90
[
1:07b0] :WRAPPER:
kernel32.dll
CreateFileMappingW = 0x7c
809420/0x004fabe0
[
1:07b0] :WRAPPER:
kernel32.dll
MapViewOfFile = 0x7c
80b995/0x004fac30
[
1:07b0] :WRAPPER:
kernel32.dll
UnmapViewOfFile = 0x7c
80ba04/0x004fac80
[
1:07b0] :WRAPPER:
kernel32.dll
FreeLibrary = 0x7c
80ac6e/0x004fa700
[
1:07b0] :WRAPPER:
kernel32.dll
LoadLibraryA = 0x7c
801d7b/0x004fa370
[
1:07b0] :WRAPPER:
kernel32.dll
LoadLibraryW = 0x7c
80aedb/0x004fa470
[
1:07b0] :WRAPPER:
kernel32.dll
LoadLibraryExA = 0x7c
801d53/0x004fa390
[
1:07b0] :WRAPPER:
kernel32.dll
LoadLibraryExW = 0x7c
801af5/0x004fa490
[
1:07b0] :WRAPPER:
kernel32.dll
GetProcAddress = 0x7c
80ae30/0x004fa5c0
[
1:07b0] :WRAPPER:
kernel32.dll
FindFirstFileA = 0x7c

813869/0x004f9990
[
1:07b0] :WRAPPER:
80ef71/0x004f99e0
[
1:07b0] :WRAPPER:
80eb0d/0x004f9b60
[
1:07b0] :WRAPPER:
80ee67/0x004f9cf0
[
1:07b0] :WRAPPER:
834ec9/0x004f9d20
[
1:07b0] :WRAPPER:
80efca/0x004f9d60
[
1:07b0] :WRAPPER:
82196a/0x004facb0
[
1:07b0] :WRAPPER:
85f738/0x004fad70
[
1:07b0] :WRAPPER:
834e7c/0x004fadc0
[
1:07b0] :WRAPPER:
8353e6/0x004fae70
[
1:07b0] :WRAPPER:
83541e/0x004fae20
[
1:07b0] :WRAPPER:
80b731/0x004fa4b0
[
1:07b0] :WRAPPER:
80e4cd/0x004fa4f0
[
1:07b0] :WRAPPER:
80e76c/0x004f9830
[
1:07b0] :WRAPPER:
8217d2/0x004f9790
[
1:07b0] :WRAPPER:
832b6e/0x004fa0c0
[
1:07b0] :WRAPPER:
83644c/0x004fa180
[
1:07b0] :WRAPPER:
832dbf/0x004fa220
[
1:07b0] :WRAPPER:
835f39/0x004fa280
[
1:07b0] :WRAPPER:
810cfd/0x004f9e30
[
1:07b0] :WRAPPER:
832379/0x004f9e70
[
1:07b0] :WRAPPER:
8322d4/0x004f9ec0
[
1:07b0] :WRAPPER:
80b55f/0x004fa070
[
1:07b0] :WRAPPER:
f0a005/0x004fa8b0
[
1:07b0] :WRAPPER:
f09d62/0x004fa8f0
[
1:07b0] :WRAPPER:
3a7c08/0x004fa840
[
3:07b0] :WRAPPER:
4d057e/0x004f84f0
[
3:07b0] :WRAPPER:
4d0526/0x004f88a0
[
3:07b0] :WRAPPER:
4e56c5/0x004f8b20
[
3:07b0] :WRAPPER:
139706/0x004f8dc0
[
3:07b0] :WRAPPER:

kernel32.dll

FindFirstFileW = 0x7c

kernel32.dll

FindFirstFileExW = 0x7c

kernel32.dll

FindClose = 0x7c

kernel32.dll

FindNextFileA = 0x7c

kernel32.dll

FindNextFileW = 0x7c

kernel32.dll

OpenFile = 0x7c

kernel32.dll

_lopen = 0x7c

kernel32.dll

_lclose = 0x7c

kernel32.dll

_lread = 0x7c

kernel32.dll

_llseek = 0x7c

kernel32.dll

GetModuleHandleA = 0x7c

kernel32.dll

GetModuleHandleW = 0x7c

kernel32.dll

SearchPathW = 0x7c

kernel32.dll

SearchPathA = 0x7c

kernel32.dll

GetPrivateProfileStringA = 0x7c

kernel32.dll

GetPrivateProfileIntA = 0x7c

kernel32.dll

GetPrivateProfileSectionNamesA = 0x7c

kernel32.dll

GetPrivateProfileSectionA = 0x7c

kernel32.dll

GetFileInformationByHandle = 0x7c

kernel32.dll

LockFile = 0x7c

kernel32.dll

UnlockFile = 0x7c

kernel32.dll

GetModuleFileNameA = 0x7c

gdi32.dll

AddFontResourceA = 0x77

gdi32.dll

RemoveFontResourceA = 0x77

user32.dll

LoadImageA = 0x7e

ole32.dll

CoCreateInstance = 0x77

ole32.dll

CoCreateInstanceEx = 0x77

ole32.dll

CoGetClassObject = 0x77

oleaut32.dll

GetRecordInfoFromGuids = 0x77

oleaut32.dll

LoadRegTypeLib = 0x77

0f9d5a/0x004f8fe0
[
3:07b0] :LAUNCHER: prepare 3 sections, packbits 0x2
[
3:07b0] :LAUNCHER:SECTION:(encrypted) raw_size: 0x0(0), virtual: 0x1000
[
3:07b0] :LAUNCHER:SECTION:(encrypted & compressed) raw_size: 0x41a00(26880
0), virtual: 0x8b000
[
29:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'KERNEL32.DLL'
[
29:07b0] :LAUNCHER: EXECUTABLE->KERNEL32.DLL TimeDateStamp: 00000000, handl
e 7c800000
[
29:07b0] :WRAPPER:LoadLibrary: KERNEL32.DLL, handle is 7c800000
[
29:07b0] :LAUNCHER:EXECUTABLE:0x004e9624 -> 0x7c801d7b: LoadLibraryA!KERNEL
32.DLL
[
29:07b0] :LAUNCHER:WRAPPER: EXECUTABLE -> KERNEL32.DLL!0x7c801d7b = LoadLib
raryA
[
29:07b0] :LAUNCHER:EXECUTABLE:0x004e9628 -> 0x7c80ae30: GetProcAddress!KERN
EL32.DLL
[
29:07b0] :LAUNCHER:WRAPPER: EXECUTABLE -> KERNEL32.DLL!0x7c80ae30 = GetProc
Address
[
30:07b0] :LAUNCHER:EXECUTABLE:0x004e962c -> 0x7c801ad4: VirtualProtect!KERN
EL32.DLL
[
30:07b0] :LAUNCHER:EXECUTABLE:0x004e9630 -> 0x7c809ae1: VirtualAlloc!KERNEL
32.DLL
[
30:07b0] :LAUNCHER:EXECUTABLE:0x004e9634 -> 0x7c809b74: VirtualFree!KERNEL3
2.DLL
[
30:07b0] :LAUNCHER:EXECUTABLE:0x004e9638 -> 0x7c81cafa: ExitProcess!KERNEL3
2.DLL
[
30:07b0] :LAUNCHER:WRAPPER: EXECUTABLE -> KERNEL32.DLL!0x7c81cafa = ExitPro
cess
[
30:07b0] :LAUNCHER: EXECUTABLE->KERNEL32.DLL Stamped
[
30:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'ADVAPI32.dll'
[
30:07b0] :LAUNCHER: EXECUTABLE->ADVAPI32.dll TimeDateStamp: 00000000, handl
e 77da0000
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c801af5 = LoadL
ibraryExW
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c80eb0d = FindF
irstFileExW
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c80efca = FindN
extFileW
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c801a28 = Creat
eFileA
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c80e4cd = GetMo
duleHandleW
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c809420 = Creat
eFileMappingW
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c82196a = OpenF
ile
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c810b07 = GetFi
leSize
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c834e7c = _lclo
se
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c80e76c = Searc
hPathW
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c810c1e = SetFi
lePointer
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c80b731 = GetMo
duleHandleA
[
30:07b0] :LAUNCHER:WRAPPER: ADVAPI32.dll -> KERNEL32.dll!0x7c80aedb = LoadL

ibraryW
[
30:07b0] :LAUNCHER:WRAPPER:
ibrary
[
30:07b0] :LAUNCHER:WRAPPER:
ile
[
30:07b0] :LAUNCHER:WRAPPER:
ViewOfFile
[
30:07b0] :LAUNCHER:WRAPPER:
eFileW
[
30:07b0] :LAUNCHER:WRAPPER:
eFileMappingA
[
30:07b0] :LAUNCHER:WRAPPER:
ewOfFile
[
30:07b0] :LAUNCHER:WRAPPER:
ibraryA
[
30:07b0] :LAUNCHER:WRAPPER:
ocAddress
[
30:07b0] :LAUNCHER:WRAPPER:
leAttributesW
[
30:07b0] :LAUNCHER:WRAPPER:
irstFileW
[
30:07b0] :LAUNCHER:WRAPPER:
lose
[
30:07b0] :LAUNCHER:WRAPPER:
ileW
[
30:07b0] :LAUNCHER:WRAPPER:
leFileNameA
[
30:07b0] :LAUNCHER:WRAPPER:
raryA
[
30:07b0] :LAUNCHER:WRAPPER:
ewOfFile
[
30:07b0] :LAUNCHER:WRAPPER:
raryW
[
30:07b0] :LAUNCHER:WRAPPER:
Address
[
30:07b0] :LAUNCHER:WRAPPER:
ndle
[
30:07b0] :LAUNCHER:WRAPPER:
rary
[
30:07b0] :LAUNCHER:WRAPPER:
ndledExceptionFilter
[
30:07b0] :LAUNCHER:WRAPPER:
leHandleW
[
30:07b0] :LAUNCHER:WRAPPER:
andledExceptionFilter
[
30:07b0] :LAUNCHER:WRAPPER:
braryA
[
30:07b0] :LAUNCHER:WRAPPER:
uleHandleW
[
30:07b0] :LAUNCHER:WRAPPER:
PathW
[
30:07b0] :LAUNCHER:WRAPPER:
FileW
[
30:07b0] :LAUNCHER:WRAPPER:
andle
[
30:07b0] :LAUNCHER:WRAPPER:
braryW
[
30:07b0] :LAUNCHER:WRAPPER:
cAddress
[
30:07b0] :LAUNCHER:WRAPPER:

ADVAPI32.dll -> KERNEL32.dll!0x7c80ac6e = FreeL


ADVAPI32.dll -> KERNEL32.dll!0x7c801812 = ReadF
ADVAPI32.dll -> KERNEL32.dll!0x7c80ba04 = Unmap
ADVAPI32.dll -> KERNEL32.dll!0x7c8107f0 = Creat
ADVAPI32.dll -> KERNEL32.dll!0x7c8094ee = Creat
ADVAPI32.dll -> KERNEL32.dll!0x7c80b995 = MapVi
ADVAPI32.dll -> KERNEL32.dll!0x7c801d7b = LoadL
ADVAPI32.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ADVAPI32.dll -> KERNEL32.dll!0x7c80b7dc = GetFi
ADVAPI32.dll -> KERNEL32.dll!0x7c80ef71 = FindF
ADVAPI32.dll -> KERNEL32.dll!0x7c80ee67 = FindC
RPCRT4.dll -> KERNEL32.dll!0x7c8107f0 = CreateF
RPCRT4.dll -> KERNEL32.dll!0x7c80b55f = GetModu
RPCRT4.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
RPCRT4.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVi
RPCRT4.dll -> KERNEL32.dll!0x7c80aedb = LoadLib
RPCRT4.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
RPCRT4.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
RPCRT4.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
RPCRT4.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
RPCRT4.dll -> KERNEL32.dll!0x7c80e4cd = GetModu
Secur32.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
Secur32.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
Secur32.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
Secur32.dll -> KERNEL32.dll!0x7c80e76c = Search
Secur32.dll -> KERNEL32.dll!0x7c8107f0 = Create
Secur32.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
Secur32.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
Secur32.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
Secur32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi

brary
[
30:07b0] :WRAPPER:LoadLibrary: ADVAPI32.dll, handle is 77da0000
[
30:07b0] :LAUNCHER:EXECUTABLE:0x004e9640 -> 0x77db4c13: GetAce!ADVAPI32.dll
[
30:07b0] :LAUNCHER: EXECUTABLE->ADVAPI32.dll Stamped
[
30:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'COMCTL32.dll'
[
31:07b0] :LAUNCHER: EXECUTABLE->COMCTL32.dll TimeDateStamp: 00000000, handl
e 00000000
[
31:07b0] :WRAPPER:LoadLibrary: COMCTL32.dll
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80ee67 = FindClo
se
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c813869 = FindFir
stFileA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c834ec9 = FindNex
tFileA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80ef71 = FindFir
stFileW
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80efca = FindNex
tFileW
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c8115cc = GetFile
AttributesA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80b7dc = GetFile
AttributesW
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
raryA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80b731 = GetModu
leHandleA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c80b55f = GetModu
leFileNameA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c810cfd = GetFile
InformationByHandle
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c832379 = LockFil
e
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c8322d4 = UnlockF
ile
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c810c1e = SetFile
Pointer
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c801a28 = CreateF
ileA
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c801812 = ReadFil
e
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c8107f0 = CreateF
ileW
[
35:07b0] :LAUNCHER:WRAPPER: msvcrt.dll -> KERNEL32.dll!0x7c81cafa = ExitPro
cess
[
36:07b0] :LAUNCHER:WRAPPER: GDI32.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVie
wOfFile
[
36:07b0] :LAUNCHER:WRAPPER: GDI32.dll -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[
36:07b0] :LAUNCHER:WRAPPER: GDI32.dll -> KERNEL32.dll!0x7c801af5 = LoadLibr
aryExW
[
36:07b0] :LAUNCHER:WRAPPER: GDI32.dll -> KERNEL32.dll!0x7c801d7b = LoadLibr
aryA

[
36:07b0] :LAUNCHER:WRAPPER:
ointer
[
36:07b0] :LAUNCHER:WRAPPER:
leMappingW
[
36:07b0] :LAUNCHER:WRAPPER:
ary
[
36:07b0] :LAUNCHER:WRAPPER:
ddress
[
36:07b0] :LAUNCHER:WRAPPER:
aryW
[
36:07b0] :LAUNCHER:WRAPPER:
thW
[
36:07b0] :LAUNCHER:WRAPPER:
dle
[
36:07b0] :LAUNCHER:WRAPPER:
leW
[
36:07b0] :LAUNCHER:WRAPPER:
fFile
[
36:07b0] :LAUNCHER:WRAPPER:
leHandleW
[
36:07b0] :LAUNCHER:WRAPPER:
athW
[
36:07b0] :LAUNCHER:WRAPPER:
raryExW
[
36:07b0] :LAUNCHER:WRAPPER:
ndle
[
36:07b0] :LAUNCHER:WRAPPER:
ewOfFile
[
36:07b0] :LAUNCHER:WRAPPER:
OfFile
[
36:07b0] :LAUNCHER:WRAPPER:
ileMappingW
[
36:07b0] :LAUNCHER:WRAPPER:
Size
[
36:07b0] :LAUNCHER:WRAPPER:
e
[
36:07b0] :LAUNCHER:WRAPPER:
se
[
36:07b0] :LAUNCHER:WRAPPER:
tFileW
[
36:07b0] :LAUNCHER:WRAPPER:
stFileW
[
36:07b0] :LAUNCHER:WRAPPER:
leFileNameA
[
36:07b0] :LAUNCHER:WRAPPER:
leHandleA
[
36:07b0] :LAUNCHER:WRAPPER:
raryA
[
36:07b0] :LAUNCHER:WRAPPER:
ndledExceptionFilter
[
36:07b0] :LAUNCHER:WRAPPER:
Address
[
36:07b0] :LAUNCHER:WRAPPER:
raryW
[
36:07b0] :LAUNCHER:WRAPPER:
rary
[
36:07b0] :LAUNCHER:WRAPPER:
ileW
[
36:07b0] :LAUNCHER:WRAPPER:
handledExceptionFilter

GDI32.dll -> KERNEL32.dll!0x7c810c1e = SetFileP


GDI32.dll -> KERNEL32.dll!0x7c809420 = CreateFi
GDI32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibr
GDI32.dll -> KERNEL32.dll!0x7c80ae30 = GetProcA
GDI32.dll -> KERNEL32.dll!0x7c80aedb = LoadLibr
GDI32.dll -> KERNEL32.dll!0x7c80e76c = SearchPa
GDI32.dll -> KERNEL32.dll!0x7c809bd7 = CloseHan
GDI32.dll -> KERNEL32.dll!0x7c8107f0 = CreateFi
GDI32.dll -> KERNEL32.dll!0x7c80b995 = MapViewO
USER32.dll -> KERNEL32.dll!0x7c80e4cd = GetModu
USER32.dll -> KERNEL32.dll!0x7c80e76c = SearchP
USER32.dll -> KERNEL32.dll!0x7c801af5 = LoadLib
USER32.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
USER32.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVi
USER32.dll -> KERNEL32.dll!0x7c80b995 = MapView
USER32.dll -> KERNEL32.dll!0x7c809420 = CreateF
USER32.dll -> KERNEL32.dll!0x7c810b07 = GetFile
USER32.dll -> KERNEL32.dll!0x7c801812 = ReadFil
USER32.dll -> KERNEL32.dll!0x7c80ee67 = FindClo
USER32.dll -> KERNEL32.dll!0x7c80efca = FindNex
USER32.dll -> KERNEL32.dll!0x7c80ef71 = FindFir
USER32.dll -> KERNEL32.dll!0x7c80b55f = GetModu
USER32.dll -> KERNEL32.dll!0x7c80b731 = GetModu
USER32.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
USER32.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
USER32.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
USER32.dll -> KERNEL32.dll!0x7c80aedb = LoadLib
USER32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
USER32.dll -> KERNEL32.dll!0x7c8107f0 = CreateF
COMCTL32.dll -> KERNEL32.dll!0x7c8449fd = SetUn

[
36:07b0] :LAUNCHER:WRAPPER:
ocAddress
[
36:07b0] :LAUNCHER:WRAPPER:
ibrary
[
36:07b0] :LAUNCHER:WRAPPER:
ibraryA
[
36:07b0] :LAUNCHER:WRAPPER:
Handle
[
36:07b0] :LAUNCHER:WRAPPER:
ibraryW
[
36:07b0] :LAUNCHER:WRAPPER:
duleHandleW
[
36:07b0] :LAUNCHER:WRAPPER:
lose
[
36:07b0] :LAUNCHER:WRAPPER:
extFileW
[
36:07b0] :LAUNCHER:WRAPPER:
irstFileW
[
36:07b0] :LAUNCHER:WRAPPER:
ewOfFile
[
36:07b0] :LAUNCHER:WRAPPER:
eFileMappingW
[
36:07b0] :LAUNCHER:WRAPPER:
leSize
[
36:07b0] :LAUNCHER:WRAPPER:
eFileW
[
36:07b0] :LAUNCHER:WRAPPER:
ViewOfFile
[
36:07b0] :LAUNCHER:WRAPPER:
duleHandleA
[
36:07b0] :LAUNCHER:WRAPPER:
ePointer
[
36:07b0] :LAUNCHER:WRAPPER:
FileA
[
36:07b0] :LAUNCHER:WRAPPER:
andledExceptionFilter
[
36:07b0] :LAUNCHER:WRAPPER:
eAttributesA
[
36:07b0] :LAUNCHER:WRAPPER:
PathA
[
36:07b0] :LAUNCHER:WRAPPER:
ose
[
36:07b0] :LAUNCHER:WRAPPER:
xtFileA
[
36:07b0] :LAUNCHER:WRAPPER:
rstFileA
[
36:07b0] :LAUNCHER:WRAPPER:
xtFileW
[
36:07b0] :LAUNCHER:WRAPPER:
FileW
[
36:07b0] :LAUNCHER:WRAPPER:
rstFileW
[
36:07b0] :LAUNCHER:WRAPPER:
eAttributesW
[
36:07b0] :LAUNCHER:WRAPPER:
PathW
[
36:07b0] :LAUNCHER:WRAPPER:
uleHandleA
[
36:07b0] :LAUNCHER:WRAPPER:
uleHandleW

COMCTL32.dll -> KERNEL32.dll!0x7c80ae30 = GetPr


COMCTL32.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
COMCTL32.dll -> KERNEL32.dll!0x7c801d7b = LoadL
COMCTL32.dll -> KERNEL32.dll!0x7c809bd7 = Close
COMCTL32.dll -> KERNEL32.dll!0x7c80aedb = LoadL
COMCTL32.dll -> KERNEL32.dll!0x7c80e4cd = GetMo
COMCTL32.dll -> KERNEL32.dll!0x7c80ee67 = FindC
COMCTL32.dll -> KERNEL32.dll!0x7c80efca = FindN
COMCTL32.dll -> KERNEL32.dll!0x7c80ef71 = FindF
COMCTL32.dll -> KERNEL32.dll!0x7c80b995 = MapVi
COMCTL32.dll -> KERNEL32.dll!0x7c809420 = Creat
COMCTL32.dll -> KERNEL32.dll!0x7c810b07 = GetFi
COMCTL32.dll -> KERNEL32.dll!0x7c8107f0 = Creat
COMCTL32.dll -> KERNEL32.dll!0x7c80ba04 = Unmap
COMCTL32.dll -> KERNEL32.dll!0x7c80b731 = GetMo
SHLWAPI.dll -> KERNEL32.dll!0x7c810c1e = SetFil
SHLWAPI.dll -> KERNEL32.dll!0x7c801a28 = Create
SHLWAPI.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
SHLWAPI.dll -> KERNEL32.dll!0x7c8115cc = GetFil
SHLWAPI.dll -> KERNEL32.dll!0x7c8217d2 = Search
SHLWAPI.dll -> KERNEL32.dll!0x7c80ee67 = FindCl
SHLWAPI.dll -> KERNEL32.dll!0x7c834ec9 = FindNe
SHLWAPI.dll -> KERNEL32.dll!0x7c813869 = FindFi
SHLWAPI.dll -> KERNEL32.dll!0x7c80efca = FindNe
SHLWAPI.dll -> KERNEL32.dll!0x7c8107f0 = Create
SHLWAPI.dll -> KERNEL32.dll!0x7c80ef71 = FindFi
SHLWAPI.dll -> KERNEL32.dll!0x7c80b7dc = GetFil
SHLWAPI.dll -> KERNEL32.dll!0x7c80e76c = Search
SHLWAPI.dll -> KERNEL32.dll!0x7c80b731 = GetMod
SHLWAPI.dll -> KERNEL32.dll!0x7c80e4cd = GetMod

[
36:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c83644c = GetPri
vateProfileIntA
[
36:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c801d53 = LoadLi
braryExA
[
36:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[
36:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[
36:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c832b6e = GetPri
vateProfileStringA
[
36:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c801812 = ReadFi
le
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c810cfd = GetFil
eInformationByHandle
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c8094ee = Create
FileMappingA
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[
37:07b0] :LAUNCHER:WRAPPER: SHLWAPI.dll -> USER32.dll!0x7e3a7c08 = LoadImag
eA
[
37:07b0] :WRAPPER:LoadLibrary: COMCTL32.dll, handle is 773a0000
[
37:07b0] :LAUNCHER:EXECUTABLE:0x004e9648 -> 0x773b5582: ImageList_Remove!CO
MCTL32.dll
[
37:07b0] :LAUNCHER: EXECUTABLE->COMCTL32.dll Stamped
[
37:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'COMDLG32.dll'
[
37:07b0] :LAUNCHER: EXECUTABLE->COMDLG32.dll TimeDateStamp: 00000000, handl
e 00000000
[
37:07b0] :WRAPPER:LoadLibrary: COMDLG32.dll
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80e4cd = GetMo
duleHandleW
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c801d7b = LoadL
ibraryA
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80aedb = LoadL
ibraryW
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80b7dc = GetFi
leAttributesW
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80ef71 = FindF
irstFileW
[
41:07b0] :LAUNCHER:WRAPPER: COMDLG32.dll -> KERNEL32.dll!0x7c80efca = FindN
extFileW

[
41:07b0] :LAUNCHER:WRAPPER:
lose
[
41:07b0] :LAUNCHER:WRAPPER:
Handle
[
41:07b0] :LAUNCHER:WRAPPER:
duleHandleA
[
41:07b0] :LAUNCHER:WRAPPER:
eFileW
[
41:07b0] :LAUNCHER:WRAPPER:
uleHandleA
[
41:07b0] :LAUNCHER:WRAPPER:
rstFileA
[
41:07b0] :LAUNCHER:WRAPPER:
xtFileA
[
41:07b0] :LAUNCHER:WRAPPER:
eInformationByHandle
[
41:07b0] :LAUNCHER:WRAPPER:
ocess
[
41:07b0] :LAUNCHER:WRAPPER:
rstFileExW
[
41:07b0] :LAUNCHER:WRAPPER:
andledExceptionFilter
[
41:07b0] :LAUNCHER:WRAPPER:
braryA
[
41:07b0] :LAUNCHER:WRAPPER:
eAttributesA
[
41:07b0] :LAUNCHER:WRAPPER:
eSize
[
41:07b0] :LAUNCHER:WRAPPER:
FileMappingW
[
41:07b0] :LAUNCHER:WRAPPER:
wOfFile
[
41:07b0] :LAUNCHER:WRAPPER:
iewOfFile
[
41:07b0] :LAUNCHER:WRAPPER:
uleHandleW
[
41:07b0] :LAUNCHER:WRAPPER:
PathW
[
41:07b0] :LAUNCHER:WRAPPER:
e
[
41:07b0] :LAUNCHER:WRAPPER:
[
41:07b0] :LAUNCHER:WRAPPER:
braryW
[
41:07b0] :LAUNCHER:WRAPPER:
cAddress
[
41:07b0] :LAUNCHER:WRAPPER:
FileW
[
41:07b0] :LAUNCHER:WRAPPER:
le
[
41:07b0] :LAUNCHER:WRAPPER:
eAttributesW
[
41:07b0] :LAUNCHER:WRAPPER:
rstFileW
[
41:07b0] :LAUNCHER:WRAPPER:
xtFileW
[
41:07b0] :LAUNCHER:WRAPPER:
ose
[
41:07b0] :LAUNCHER:WRAPPER:
andle
[
41:07b0] :LAUNCHER:WRAPPER:

COMDLG32.dll -> KERNEL32.dll!0x7c80ee67 = FindC


COMDLG32.dll -> KERNEL32.dll!0x7c809bd7 = Close
COMDLG32.dll -> KERNEL32.dll!0x7c80b731 = GetMo
COMDLG32.dll -> KERNEL32.dll!0x7c8107f0 = Creat
SHELL32.dll -> KERNEL32.dll!0x7c80b731 = GetMod
SHELL32.dll -> KERNEL32.dll!0x7c813869 = FindFi
SHELL32.dll -> KERNEL32.dll!0x7c834ec9 = FindNe
SHELL32.dll -> KERNEL32.dll!0x7c810cfd = GetFil
SHELL32.dll -> KERNEL32.dll!0x7c81cafa = ExitPr
SHELL32.dll -> KERNEL32.dll!0x7c80eb0d = FindFi
SHELL32.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
SHELL32.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
SHELL32.dll -> KERNEL32.dll!0x7c8115cc = GetFil
SHELL32.dll -> KERNEL32.dll!0x7c810b07 = GetFil
SHELL32.dll -> KERNEL32.dll!0x7c809420 = Create
SHELL32.dll -> KERNEL32.dll!0x7c80b995 = MapVie
SHELL32.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
SHELL32.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
SHELL32.dll -> KERNEL32.dll!0x7c80e76c = Search
SHELL32.dll -> KERNEL32.dll!0x7c834e7c = _lclos
SHELL32.dll -> KERNEL32.dll!0x7c8353e6 = _lread
SHELL32.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
SHELL32.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
SHELL32.dll -> KERNEL32.dll!0x7c8107f0 = Create
SHELL32.dll -> KERNEL32.dll!0x7c801812 = ReadFi
SHELL32.dll -> KERNEL32.dll!0x7c80b7dc = GetFil
SHELL32.dll -> KERNEL32.dll!0x7c80ef71 = FindFi
SHELL32.dll -> KERNEL32.dll!0x7c80efca = FindNe
SHELL32.dll -> KERNEL32.dll!0x7c80ee67 = FindCl
SHELL32.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
SHELL32.dll -> KERNEL32.dll!0x7c810c1e = SetFil

ePointer
[
41:07b0] :LAUNCHER:WRAPPER: SHELL32.dll -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[
41:07b0] :LAUNCHER:WRAPPER: SHELL32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
41:07b0] :LAUNCHER:WRAPPER: SHELL32.dll -> KERNEL32.dll!0x7c801d53 = LoadLi
braryExA
[
41:07b0] :WRAPPER:LoadLibrary: COMDLG32.dll, handle is 76360000
[
41:07b0] :LAUNCHER:EXECUTABLE:0x004e9650 -> 0x76377c2b: GetSaveFileNameW!CO
MDLG32.dll
[
41:07b0] :LAUNCHER: EXECUTABLE->COMDLG32.dll Stamped
[
41:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'GDI32.dll'
[
41:07b0] :LAUNCHER: EXECUTABLE->GDI32.dll TimeDateStamp: 00000000, handle 7
7ef0000
[
41:07b0] :WRAPPER:LoadLibrary: GDI32.dll, handle is 77ef0000
[
41:07b0] :LAUNCHER:EXECUTABLE:0x004e9658 -> 0x77efd987: LineTo!GDI32.dll
[
41:07b0] :LAUNCHER: EXECUTABLE->GDI32.dll Stamped
[
41:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'MPR.dll'
[
42:07b0] :LAUNCHER: EXECUTABLE->MPR.dll TimeDateStamp: 00000000, handle 000
00000
[
42:07b0] :WRAPPER:LoadLibrary: MPR.dll
[
42:07b0] :LAUNCHER:WRAPPER: MPR.dll -> KERNEL32.dll!0x7c801d7b = LoadLibrar
yA
[
42:07b0] :LAUNCHER:WRAPPER: MPR.dll -> KERNEL32.dll!0x7c8449fd = SetUnhandl
edExceptionFilter
[
42:07b0] :LAUNCHER:WRAPPER: MPR.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibrar
y
[
42:07b0] :LAUNCHER:WRAPPER: MPR.dll -> KERNEL32.dll!0x7c801af5 = LoadLibrar
yExW
[
42:07b0] :LAUNCHER:WRAPPER: MPR.dll -> KERNEL32.dll!0x7c80ae30 = GetProcAdd
ress
[
42:07b0] :LAUNCHER:WRAPPER: MPR.dll -> KERNEL32.dll!0x7c809bd7 = CloseHandl
e
[
42:07b0] :WRAPPER:LoadLibrary: MPR.dll, handle is 71aa0000
[
42:07b0] :LAUNCHER:EXECUTABLE:0x004e9660 -> 0x71aa1e09: WNetGetConnectionW!
MPR.dll
[
42:07b0] :LAUNCHER: EXECUTABLE->MPR.dll Stamped
[
42:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'ole32.dll'
[
42:07b0] :LAUNCHER: EXECUTABLE->ole32.dll TimeDateStamp: 00000000, handle 7
74b0000
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80b7dc = GetFileA
ttributesW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80ae30 = GetProcA
ddress
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c801d7b = LoadLibr
aryA
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c809bd7 = CloseHan
dle
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibr
ary
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80aedb = LoadLibr
aryW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c8107f0 = CreateFi
leW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80ee67 = FindClos
e
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80ef71 = FindFirs
tFileW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80e4cd = GetModul
eHandleW

[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c801af5 = LoadLibr
aryExW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c801812 = ReadFile
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c810c1e = SetFileP
ointer
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c809420 = CreateFi
leMappingW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80b995 = MapViewO
fFile
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVie
wOfFile
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c801d53 = LoadLibr
aryExA
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c80e76c = SearchPa
thW
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c832379 = LockFile
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c8322d4 = UnlockFi
le
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c810b07 = GetFileS
ize
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c810cfd = GetFileI
nformationByHandle
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c8094ee = CreateFi
leMappingA
[
42:07b0] :LAUNCHER:WRAPPER: ole32.dll -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[
43:07b0] :WRAPPER:LoadLibrary: ole32.dll, handle is 774b0000
[
43:07b0] :LAUNCHER:EXECUTABLE:0x004e9668 -> 0x774d2a53: CoInitialize!ole32.
dll
[
43:07b0] :LAUNCHER: EXECUTABLE->ole32.dll Stamped
[
43:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'OLEAUT32.dll'
[
43:07b0] :LAUNCHER: EXECUTABLE->OLEAUT32.dll TimeDateStamp: 00000000, handl
e 770f0000
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c801d7b = LoadL
ibraryA
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c834e7c = _lclo
se
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c8353e6 = _lrea
d
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c83541e = _llse
ek
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c801a28 = Creat
eFileA
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c8107f0 = Creat
eFileW
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80aedb = LoadL
ibraryW
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c8217d2 = Searc
hPathA
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80e76c = Searc
hPathW
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80ba04 = Unmap
ViewOfFile
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80b995 = MapVi
ewOfFile
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c8094ee = Creat

eFileMappingA
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c810b07 = GetFi
leSize
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> KERNEL32.dll!0x7c80b731 = GetMo
duleHandleA
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> ole32.dll!0x774d057e = CoCreate
Instance
[
43:07b0] :LAUNCHER:WRAPPER: OLEAUT32.dll -> ole32.dll!0x774e56c5 = CoGetCla
ssObject
[
43:07b0] :WRAPPER:LoadLibrary: OLEAUT32.dll, handle is 770f0000
[
43:07b0] :LAUNCHER:EXECUTABLE:0x004e9670 -> 0x770f4950: 8!OLEAUT32.dll
[
43:07b0] :LAUNCHER: EXECUTABLE->OLEAUT32.dll Stamped
[
43:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'PSAPI.DLL'
[
43:07b0] :LAUNCHER: EXECUTABLE->PSAPI.DLL TimeDateStamp: 00000000, handle 0
0000000
[
43:07b0] :WRAPPER:LoadLibrary: PSAPI.DLL
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c801d7b = LoadLibr
aryA
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c80ac6e = FreeLibr
ary
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c80ae30 = GetProcA
ddress
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c80b995 = MapViewO
fFile
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c80ba04 = UnmapVie
wOfFile
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c801a28 = CreateFi
leA
[
43:07b0] :LAUNCHER:WRAPPER: PSAPI.DLL -> KERNEL32.dll!0x7c809bd7 = CloseHan
dle
[
44:07b0] :WRAPPER:LoadLibrary: PSAPI.DLL, handle is 76bb0000
[
44:07b0] :LAUNCHER:EXECUTABLE:0x004e9678 -> 0x76bb3a76: EnumProcesses!PSAPI
.DLL
[
44:07b0] :LAUNCHER: EXECUTABLE->PSAPI.DLL Stamped
[
44:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'SHELL32.dll'
[
44:07b0] :LAUNCHER: EXECUTABLE->SHELL32.dll TimeDateStamp: 00000000, handle
7e6a0000
[
44:07b0] :WRAPPER:LoadLibrary: SHELL32.dll, handle is 7e6a0000
[
44:07b0] :LAUNCHER:EXECUTABLE:0x004e9680 -> 0x7e757c18: DragFinish!SHELL32.
dll
[
44:07b0] :LAUNCHER: EXECUTABLE->SHELL32.dll Stamped
[
44:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'USER32.dll'
[
44:07b0] :LAUNCHER: EXECUTABLE->USER32.dll TimeDateStamp: 00000000, handle
7e390000
[
44:07b0] :WRAPPER:LoadLibrary: USER32.dll, handle is 7e390000
[
44:07b0] :LAUNCHER:EXECUTABLE:0x004e9688 -> 0x7e3986c7: GetDC!USER32.dll
[
44:07b0] :LAUNCHER: EXECUTABLE->USER32.dll Stamped
[
44:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'USERENV.dll'
[
44:07b0] :LAUNCHER: EXECUTABLE->USERENV.dll TimeDateStamp: 00000000, handle
00000000
[
44:07b0] :WRAPPER:LoadLibrary: USERENV.dll
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c810c1e = SetFil

ePointer
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c801d53 = LoadLi
braryExA
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80b7dc = GetFil
eAttributesW
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80e76c = Search
PathW
[
44:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80ee67 = FindCl
ose
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80efca = FindNe
xtFileW
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c80ef71 = FindFi
rstFileW
[
45:07b0] :LAUNCHER:WRAPPER: USERENV.dll -> KERNEL32.dll!0x7c801812 = ReadFi
le
[
45:07b0] :WRAPPER:LoadLibrary: USERENV.dll, handle is 76630000
[
45:07b0] :LAUNCHER:EXECUTABLE:0x004e9690 -> 0x7663ad1c: LoadUserProfileW!US
ERENV.dll
[
45:07b0] :LAUNCHER: EXECUTABLE->USERENV.dll Stamped
[
45:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'VERSION.dll'
[
45:07b0] :LAUNCHER: EXECUTABLE->VERSION.dll TimeDateStamp: 00000000, handle
00000000
[
45:07b0] :WRAPPER:LoadLibrary: VERSION.dll
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c834e7c = _lclos
e
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c85f738 = _lopen
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c8353e6 = _lread
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c83541e = _llsee
k
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c80b7dc = GetFil
eAttributesW
[
45:07b0] :LAUNCHER:WRAPPER: VERSION.dll -> KERNEL32.dll!0x7c8449fd = SetUnh

andledExceptionFilter
[
45:07b0] :WRAPPER:LoadLibrary: VERSION.dll, handle is 77bd0000
[
45:07b0] :LAUNCHER:EXECUTABLE:0x004e9698 -> 0x77bd1805: VerQueryValueW!VERS
ION.dll
[
45:07b0] :LAUNCHER: EXECUTABLE->VERSION.dll Stamped
[
45:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'WININET.dll'
[
45:07b0] :LAUNCHER: EXECUTABLE->WININET.dll TimeDateStamp: 00000000, handle
00000000
[
45:07b0] :WRAPPER:LoadLibrary: WININET.dll
[
50:07b0] :WRAPPER:LoadLibrary: comctl32.dll, handle is 773a0000
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c801a28 = Create
FileA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c8115cc = GetFil
eAttributesA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80b7dc = GetFil
eAttributesW
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c801d53 = LoadLi
braryExA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c813869 = FindFi
rstFileA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80ef71 = FindFi
rstFileW
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c834ec9 = FindNe
xtFileA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80efca = FindNe
xtFileW
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c801812 = ReadFi
le
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80ee67 = FindCl
ose
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c8094ee = Create
FileMappingA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c809420 = Create
FileMappingW
[
50:07b0] :LAUNCHER:WRAPPER: CRYPT32.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA

[
50:07b0] :LAUNCHER:WRAPPER: MSASN1.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[
50:07b0] :LAUNCHER:WRAPPER: MSASN1.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
raryA
[
50:07b0] :LAUNCHER:WRAPPER: MSASN1.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[
50:07b0] :LAUNCHER:WRAPPER: MSASN1.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[
50:07b0] :LAUNCHER:WRAPPER: MSASN1.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c801812 = ReadFi
le
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c8115cc = GetFil
eAttributesA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c832b6e = GetPri
vateProfileStringA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80ee67 = FindCl
ose
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c834ec9 = FindNe
xtFileA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c813869 = FindFi
rstFileA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c8094ee = Create
FileMappingA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c801d53 = LoadLi
braryExA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c801a28 = Create
FileA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[
51:07b0] :LAUNCHER:WRAPPER: WININET.dll -> USER32.dll!0x7e3a7c08 = LoadImag
eA
[
51:07b0] :WRAPPER:LoadLibrary: WININET.dll, handle is 77180000
[
51:07b0] :LAUNCHER:EXECUTABLE:0x004e96a0 -> 0x771d5d0c: FtpOpenFileW!WININE
T.dll
[
51:07b0] :LAUNCHER: EXECUTABLE->WININET.dll Stamped
[
51:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'WINMM.dll'
[
51:07b0] :LAUNCHER: EXECUTABLE->WINMM.dll TimeDateStamp: 00000000, handle 0
0000000
[
51:07b0] :WRAPPER:LoadLibrary: WINMM.dll

[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80b995 = MapViewO
fFile
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVie
wOfFile
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c801d7b = LoadLibr
aryA
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c810b07 = GetFileS
ize
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c834e7c = _lclose
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80b7dc = GetFileA
ttributesW
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c83541e = _llseek
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c8353e6 = _lread
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c801af5 = LoadLibr
aryExW
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c809bd7 = CloseHan
dle
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80e76c = SearchPa
thW
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c8107f0 = CreateFi
leW
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80ae30 = GetProcA
ddress
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80e4cd = GetModul
eHandleW
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80b55f = GetModul
eFileNameA
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80aedb = LoadLibr
aryW
[
52:07b0] :LAUNCHER:WRAPPER: WINMM.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibr
ary
[
52:07b0] :WRAPPER:LoadLibrary: WINMM.dll, handle is 76b00000
[
52:07b0] :LAUNCHER:EXECUTABLE:0x004e96a8 -> 0x76b04e4f: timeGetTime!WINMM.d
ll
[
52:07b0] :LAUNCHER: EXECUTABLE->WINMM.dll Stamped
[
52:07b0] :LAUNCHER:EXECUTABLE dynamic link to 'WSOCK32.dll'
[
52:07b0] :LAUNCHER: EXECUTABLE->WSOCK32.dll TimeDateStamp: 00000000, handle
00000000
[
52:07b0] :WRAPPER:LoadLibrary: WSOCK32.dll
[
52:07b0] :LAUNCHER:WRAPPER: WS2_32.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[
52:07b0] :LAUNCHER:WRAPPER: WS2_32.dll -> KERNEL32.dll!0x7c80b55f = GetModu
leFileNameA
[
53:07b0] :LAUNCHER:WRAPPER: WS2_32.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
raryA
[
53:07b0] :LAUNCHER:WRAPPER: WS2_32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[
53:07b0] :LAUNCHER:WRAPPER: WS2_32.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[
53:07b0] :LAUNCHER:WRAPPER: WS2_32.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c809bd7 = CloseH

andle
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[
53:07b0] :LAUNCHER:WRAPPER: WS2HELP.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
53:07b0] :WRAPPER:LoadLibrary: WSOCK32.dll, handle is 71a50000
[
53:07b0] :LAUNCHER:EXECUTABLE:0x004e96b0 -> 0x71a52e70: 16!WSOCK32.dll
[
53:07b0] :LAUNCHER: EXECUTABLE->WSOCK32.dll Stamped
[
53:07b0] :LAUNCHER: Goto real entry point 0x4cce80
[
58:07b0] :WRAPPER:LoadLibrary: KERNEL32.DLL, handle is 7c800000
[
58:07b0] :WRAPPER:LoadLibrary: ADVAPI32.dll, handle is 77da0000
[
58:07b0] :WRAPPER:LoadLibrary: COMCTL32.dll, handle is 773a0000
[
59:07b0] :WRAPPER:LoadLibrary: COMDLG32.dll, handle is 76360000
[
59:07b0] :WRAPPER:LoadLibrary: GDI32.dll, handle is 77ef0000
[
59:07b0] :WRAPPER:LoadLibrary: MPR.dll, handle is 71aa0000
[
59:07b0] :WRAPPER:LoadLibrary: ole32.dll, handle is 774b0000
[
59:07b0] :WRAPPER:LoadLibrary: OLEAUT32.dll, handle is 770f0000
[
59:07b0] :WRAPPER:LoadLibrary: PSAPI.DLL, handle is 76bb0000
[
60:07b0] :WRAPPER:LoadLibrary: SHELL32.dll, handle is 7e6a0000
[
60:07b0] :WRAPPER:LoadLibrary: USER32.dll, handle is 7e390000
[
60:07b0] :WRAPPER:LoadLibrary: USERENV.dll, handle is 76630000
[
60:07b0] :WRAPPER:LoadLibrary: VERSION.dll, handle is 77bd0000
[
60:07b0] :WRAPPER:LoadLibrary: WININET.dll, handle is 77180000
[
60:07b0] :WRAPPER:LoadLibrary: WINMM.dll, handle is 76b00000
[
61:07b0] :WRAPPER:LoadLibrary: WSOCK32.dll, handle is 71a50000
[
61:07b0] :WRAPPER:SetUnhandledExceptionFilter: 0x0041f20e
[
61:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[
61:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[
61:07b0] :WRAPPER:LoadLibrary: uxtheme.dll
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80b7dc = GetFil
eAttributesW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c801812 = ReadFi
le
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80ef71 = FindFi
rstFileW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80efca = FindNe
xtFileW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80ee67 = FindCl
ose
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c809420 = Create
FileMappingW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
uleHandleW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c8107f0 = Create

FileW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[
62:07b0] :LAUNCHER:WRAPPER: uxtheme.dll -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[
62:07b0] :WRAPPER:LoadLibrary: uxtheme.dll, handle is 5b150000
[
62:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\uxtheme.dll, handle is 5
b150000
[
63:07b0] :WRAPPER:LoadLibrary: uxtheme.dll, handle is 5b150000
[
63:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\uxtheme.dll, handle is 5
b150000
[
63:07b0] :WRAPPER:FreeLibrary:5b150000, 'C:\WINDOWS\system32\uxtheme.dll'
[
63:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\uxtheme.dll, handle is 5
b150000
[
63:07b0] :WRAPPER:FreeLibrary:5b150000, 'C:\WINDOWS\system32\uxtheme.dll'
[
64:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\uxtheme.dll, handle is 5
b150000
[
64:07b0] :WRAPPER:FreeLibrary:5b150000, 'C:\WINDOWS\system32\uxtheme.dll'
[
64:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5
7043f)
[
64:07b0] :BOX: ReadFile 0x008ff834 <- 0x10000 bytes at 0x0 'TRAINER V4.EXE'
[
69:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x0 'TRAINER V4.EX
E'
[
69:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x10000->0x10000 'T
RAINER V4.EXE'
[
69:07b0] :BOX: SetFilePointer(OK): SET 65516(0xffec)/0x57043f, 0x10000->0xf
fec 'TRAINER V4.EXE'
[
69:07b0] :BOX: ReadFile 0x008ff834 <- 0x10000 bytes at 0xffec 'TRAINER V4.E
XE'
[
74:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0xffec 'TRAINER V4
.EXE'
[
74:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x1ffec->0x1ffec 'T
RAINER V4.EXE'
[
74:07b0] :BOX: SetFilePointer(OK): SET 131032(0x1ffd8)/0x57043f, 0x1ffec->0
x1ffd8 'TRAINER V4.EXE'
[
74:07b0] :BOX: ReadFile 0x008ff834 <- 0x10000 bytes at 0x1ffd8 'TRAINER V4.
EXE'
[
79:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x1ffd8 'TRAINER V
4.EXE'
[
80:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x2ffd8->0x2ffd8 'T
RAINER V4.EXE'
[
80:07b0] :BOX: SetFilePointer(OK): SET 196548(0x2ffc4)/0x57043f, 0x2ffd8->0
x2ffc4 'TRAINER V4.EXE'
[
80:07b0] :BOX: ReadFile 0x008ff834 <- 0x10000 bytes at 0x2ffc4 'TRAINER V4.
EXE'
[
85:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x2ffc4 'TRAINER V
4.EXE'
[
85:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x3ffc4->0x3ffc4 'T
RAINER V4.EXE'
[
85:07b0] :BOX: SetFilePointer(OK): SET 262064(0x3ffb0)/0x57043f, 0x3ffc4->0
x3ffb0 'TRAINER V4.EXE'
[
85:07b0] :BOX: ReadFile 0x008ff834 <- 0x10000 bytes at 0x3ffb0 'TRAINER V4.
EXE'
[
90:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x3ffb0 'TRAINER V
4.EXE'
[
90:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x4ffb0->0x4ffb0 'T
RAINER V4.EXE'
[
90:07b0] :BOX: SetFilePointer(OK): SET 327580(0x4ff9c)/0x57043f, 0x4ffb0->0

x4ff9c 'TRAINER V4.EXE'


[
90:07b0] :BOX: ReadFile 0x008ff834 <- 0x10000 bytes at 0x4ff9c 'TRAINER V4.
EXE'
[
94:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x4ff9c 'TRAINER V
4.EXE'
[
94:07b0] :BOX: SetFilePointer(OK): SET 385044(0x5e014)/0x57043f, 0x5ff9c->0
x5e014 'TRAINER V4.EXE'
[
94:07b0] :BOX: ReadFile 0x011a4d18 <- 0x1000 bytes at 0x5e014 'TRAINER V4.E
XE'
[
94:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x5e014 'TRAINER V4.
EXE'
[
94:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5f014->0x5f014 'T
RAINER V4.EXE'
[
94:07b0] :BOX: SetFilePointer(OK): SET 385064(0x5e028)/0x57043f, 0x5f014->0
x5e028 'TRAINER V4.EXE'
[
94:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0x5e028 'TRAINER V4.EX
E'
[
94:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e028 'TRAINER V4.EX
E'
[
94:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e228->0x5e228 'T
RAINER V4.EXE'
[
94:07b0] :BOX: SetFilePointer(OK): SET 385207(0x5e0b7)/0x57043f, 0x5e228->0
x5e0b7 'TRAINER V4.EXE'
[
94:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0x5e0b7 'TRAINER V4.EX
E'
[
94:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e0b7 'TRAINER V4.EX
E'
[
94:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e2b7->0x5e2b7 'T
RAINER V4.EXE'
[
94:07b0] :BOX: SetFilePointer(OK): SET 774007(0xbcf77)/0x57043f, 0x5e2b7->0
xbcf77 'TRAINER V4.EXE'
[
94:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0xbcf77 'TRAINER V4.EX
E'
[
99:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0xbcf77 'TRAINER V4.EX
E'
[
99:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0xbd177->0xbd177 'T
RAINER V4.EXE'
[
99:07b0] :BOX: SetFilePointer(OK): SET 774056(0xbcfa8)/0x57043f, 0xbd177->0
xbcfa8 'TRAINER V4.EXE'
[
99:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0xbcfa8 'TRAINER V4.EX
E'
[
99:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0xbcfa8 'TRAINER V4.EX
E'
[ 100:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0xbd1a8->0xbd1a8 'T
RAINER V4.EXE'
[ 100:07b0] :BOX: SetFilePointer(OK): SET 5664206(0x566dce)/0x57043f, 0xbd1a8>0x566dce 'TRAINER V4.EXE'
[ 100:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0x566dce 'TRAINER V4.E
XE'
[ 104:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x566dce 'TRAINER V4.E
XE'
[ 104:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x566fce->0x566fce
'TRAINER V4.EXE'
[ 104:07b0] :BOX: SetFilePointer(OK): SET 5664417(0x566ea1)/0x57043f, 0x566fce
->0x566ea1 'TRAINER V4.EXE'
[ 105:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0x566ea1 'TRAINER V4.E
XE'
[ 105:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x566ea1 'TRAINER V4.E
XE'
[ 105:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5670a1->0x5670a1

'TRAINER V4.EXE'
[ 105:07b0] :BOX: SetFilePointer(OK): SET 5702711(0x570437)/0x57043f, 0x5670a1
->0x570437 'TRAINER V4.EXE'
[ 105:07b0] :BOX: ReadFile 0x011a4d18 <- 0x200 bytes at 0x570437 'TRAINER V4.E
XE'
[ 105:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x8 offs 0x570437 'TRAINER V4.EXE
'
[ 105:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 105:07b0] :WRAPPER:LoadLibrary: ole32.dll, handle is 774b0000
[ 106:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\SHELL32.dll, handle is 7
e6a0000
[ 106:07b0] :WRAPPER:LoadLibrary: SETUPAPI.dll
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80e4cd = GetMo
duleHandleW
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c801d7b = LoadL
ibraryA
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80efca = FindN
extFileW
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80e76c = Searc
hPathW
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80b7dc = GetFi
leAttributesW
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80ba04 = Unmap
ViewOfFile
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80b995 = MapVi
ewOfFile
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c809420 = Creat
eFileMappingW
[ 106:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c810b07 = GetFi
leSize
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c8107f0 = Creat
eFileW
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c810c1e = SetFi
lePointer
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80aedb = LoadL
ibraryW
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80ee67 = FindC
lose
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c80ef71 = FindF
irstFileW
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c801a28 = Creat
eFileA
[ 107:07b0] :LAUNCHER:WRAPPER: SETUPAPI.dll -> KERNEL32.dll!0x7c801812 = ReadF
ile
[ 107:07b0] :WRAPPER:LoadLibrary: SETUPAPI.dll, handle is 778f0000
[ 107:07b0] :WRAPPER:LoadLibrary: rpcrt4.dll, handle is 77e50000
[ 112:07b0] :WRAPPER:FindFirstFileExW C:\Documents and Settings,
[ 112:07b0] :WRAPPER:LoadLibrary: SHELL32.dll, handle is 7e6a0000
[ 113:07b0] :WRAPPER:LoadLibrary: ole32.dll, handle is 774b0000
[ 113:07b0] :WRAPPER:FindFirstFileExW C:\Documents and Settings\CABINA9,
[ 113:07b0] :WRAPPER:FindFirstFileExW C:\Documents and Settings\CABINA9\Mis do
cumentos,

[ 114:07b0] :WRAPPER:FindFirstFileExW C:\Documents and Settings\CABINA9\Mis do


cumentos\Downloads,
[ 114:07b0] :WRAPPER:FindFirstFileExW C:\Documents and Settings\CABINA9\Mis do
cumentos\Downloads\trainer v4,
[ 114:07b0] :WRAPPER:FindFirstFileExW C:\Documents and Settings\CABINA9\Mis do
cumentos\Downloads\trainer v4\trainer v4.exe,
[ 114:07b0] :BOX: enumeration in root of package is disabled
[ 115:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5
7043f)
[ 115:07b0] :BOX: ReadFile 0x008ff7cc <- 0x10000 bytes at 0x0 'TRAINER V4.EXE'
[ 120:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x0 'TRAINER V4.EX
E'
[ 120:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x10000->0x10000 'T
RAINER V4.EXE'
[ 120:07b0] :BOX: SetFilePointer(OK): SET 65516(0xffec)/0x57043f, 0x10000->0xf
fec 'TRAINER V4.EXE'
[ 120:07b0] :BOX: ReadFile 0x008ff7cc <- 0x10000 bytes at 0xffec 'TRAINER V4.E
XE'
[ 125:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0xffec 'TRAINER V4
.EXE'
[ 125:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x1ffec->0x1ffec 'T
RAINER V4.EXE'
[ 125:07b0] :BOX: SetFilePointer(OK): SET 131032(0x1ffd8)/0x57043f, 0x1ffec->0
x1ffd8 'TRAINER V4.EXE'
[ 125:07b0] :BOX: ReadFile 0x008ff7cc <- 0x10000 bytes at 0x1ffd8 'TRAINER V4.
EXE'
[ 130:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x1ffd8 'TRAINER V
4.EXE'
[ 131:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x2ffd8->0x2ffd8 'T
RAINER V4.EXE'
[ 131:07b0] :BOX: SetFilePointer(OK): SET 196548(0x2ffc4)/0x57043f, 0x2ffd8->0
x2ffc4 'TRAINER V4.EXE'
[ 131:07b0] :BOX: ReadFile 0x008ff7cc <- 0x10000 bytes at 0x2ffc4 'TRAINER V4.
EXE'
[ 135:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x2ffc4 'TRAINER V
4.EXE'
[ 136:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x3ffc4->0x3ffc4 'T
RAINER V4.EXE'
[ 136:07b0] :BOX: SetFilePointer(OK): SET 262064(0x3ffb0)/0x57043f, 0x3ffc4->0
x3ffb0 'TRAINER V4.EXE'
[ 136:07b0] :BOX: ReadFile 0x008ff7cc <- 0x10000 bytes at 0x3ffb0 'TRAINER V4.
EXE'
[ 141:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x3ffb0 'TRAINER V
4.EXE'
[ 141:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x4ffb0->0x4ffb0 'T
RAINER V4.EXE'
[ 141:07b0] :BOX: SetFilePointer(OK): SET 327580(0x4ff9c)/0x57043f, 0x4ffb0->0
x4ff9c 'TRAINER V4.EXE'
[ 141:07b0] :BOX: ReadFile 0x008ff7cc <- 0x10000 bytes at 0x4ff9c 'TRAINER V4.
EXE'
[ 145:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x4ff9c 'TRAINER V
4.EXE'
[ 145:07b0] :BOX: SetFilePointer(OK): SET 385044(0x5e014)/0x57043f, 0x5ff9c->0
x5e014 'TRAINER V4.EXE'
[ 145:07b0] :BOX: ReadFile 0x011a51b0 <- 0x1000 bytes at 0x5e014 'TRAINER V4.E
XE'
[ 145:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x5e014 'TRAINER V4.
EXE'
[ 145:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5f014->0x5f014 'T
RAINER V4.EXE'

[ 145:07b0] :BOX: SetFilePointer(OK): SET 385064(0x5e028)/0x57043f, 0x5f014->0


x5e028 'TRAINER V4.EXE'
[ 145:07b0] :BOX: ReadFile 0x011a51b0 <- 0x200 bytes at 0x5e028 'TRAINER V4.EX
E'
[ 145:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e028 'TRAINER V4.EX
E'
[ 145:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e228->0x5e228 'T
RAINER V4.EXE'
[ 145:07b0] :BOX: SetFilePointer(OK): SET 385235(0x5e0d3)/0x57043f, 0x5e228->0
x5e0d3 'TRAINER V4.EXE'
[ 145:07b0] :BOX: ReadFile 0x01490048 <- 0x5ee00 bytes at 0x5e0d3 'TRAINER V4.
EXE'
[ 175:07b0] :BOX: ReadFile(OK) 0x5ee00 wasread 0x5ee00 offs 0x5e0d3 'TRAINER V
4.EXE'
[ 175:07b0] :BOX: ReadFile 0x011a51b0 <- 0x200 bytes at 0xbced3 'TRAINER V4.EX
E'
[ 175:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0xbced3 'TRAINER V4.EX
E'
[ 422:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 439:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\MSCTF.dll
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c801d7b = LoadLibraryA
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80aedb = LoadLibraryW
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c8449fd = SetUnhandledExceptionFilter
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c8094ee = CreateFileMappingA
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80b995 = MapViewOfFile
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80ba04 = UnmapViewOfFile
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c809bd7 = CloseHandle
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80b55f = GetModuleFileNameA
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80ae30 = GetProcAddress
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80ac6e = FreeLibrary
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c80b731 = GetModuleHandleA
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> KERNEL32.dll!0
x7c801d53 = LoadLibraryExA
[ 440:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\MSCTF.dll -> USER32.dll!0x7
e3a7c08 = LoadImageA
[ 440:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\MSCTF.dll, handle is 746
b0000
[ 441:07b0] :WRAPPER:LoadLibrary: UxTheme.dll, handle is 5b150000
[ 447:07b0] :WRAPPER:FindFirstFileW C:\DOCUME~1\CABINA9\CONFIG~1\Temp\vscfnjs
[ 447:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5
7043f)
[ 447:07b0] :BOX: ReadFile 0x008feafc <- 0x10000 bytes at 0x0 'TRAINER V4.EXE'
[ 453:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x0 'TRAINER V4.EX
E'
[ 453:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x10000->0x10000 'T
RAINER V4.EXE'
[ 453:07b0] :BOX: SetFilePointer(OK): SET 65516(0xffec)/0x57043f, 0x10000->0xf
fec 'TRAINER V4.EXE'
[ 453:07b0] :BOX: ReadFile 0x008feafc <- 0x10000 bytes at 0xffec 'TRAINER V4.E

XE'
[ 458:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0xffec 'TRAINER V4
.EXE'
[ 458:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x1ffec->0x1ffec 'T
RAINER V4.EXE'
[ 458:07b0] :BOX: SetFilePointer(OK): SET 131032(0x1ffd8)/0x57043f, 0x1ffec->0
x1ffd8 'TRAINER V4.EXE'
[ 458:07b0] :BOX: ReadFile 0x008feafc <- 0x10000 bytes at 0x1ffd8 'TRAINER V4.
EXE'
[ 463:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x1ffd8 'TRAINER V
4.EXE'
[ 463:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x2ffd8->0x2ffd8 'T
RAINER V4.EXE'
[ 463:07b0] :BOX: SetFilePointer(OK): SET 196548(0x2ffc4)/0x57043f, 0x2ffd8->0
x2ffc4 'TRAINER V4.EXE'
[ 463:07b0] :BOX: ReadFile 0x008feafc <- 0x10000 bytes at 0x2ffc4 'TRAINER V4.
EXE'
[ 468:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x2ffc4 'TRAINER V
4.EXE'
[ 468:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x3ffc4->0x3ffc4 'T
RAINER V4.EXE'
[ 468:07b0] :BOX: SetFilePointer(OK): SET 262064(0x3ffb0)/0x57043f, 0x3ffc4->0
x3ffb0 'TRAINER V4.EXE'
[ 468:07b0] :BOX: ReadFile 0x008feafc <- 0x10000 bytes at 0x3ffb0 'TRAINER V4.
EXE'
[ 473:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x3ffb0 'TRAINER V
4.EXE'
[ 473:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x4ffb0->0x4ffb0 'T
RAINER V4.EXE'
[ 473:07b0] :BOX: SetFilePointer(OK): SET 327580(0x4ff9c)/0x57043f, 0x4ffb0->0
x4ff9c 'TRAINER V4.EXE'
[ 473:07b0] :BOX: ReadFile 0x008feafc <- 0x10000 bytes at 0x4ff9c 'TRAINER V4.
EXE'
[ 477:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x4ff9c 'TRAINER V
4.EXE'
[ 478:07b0] :BOX: SetFilePointer(OK): SET 385044(0x5e014)/0x57043f, 0x5ff9c->0
x5e014 'TRAINER V4.EXE'
[ 478:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x1000 bytes at 0x5e014 'TRAINER V4.E
XE'
[ 478:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x5e014 'TRAINER V4.
EXE'
[ 478:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5f014->0x5f014 'T
RAINER V4.EXE'
[ 478:07b0] :WRAPPER:FindFirstFileW C:\DOCUME~1\CABINA9\CONFIG~1\Temp\vscfnjs
[ 478:07b0] :BOX: SetFilePointer(OK): SET 385064(0x5e028)/0x57043f, 0x5f014->0
x5e028 'TRAINER V4.EXE'
[ 478:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x200 bytes at 0x5e028 'TRAINER V4.EX
E'
[ 478:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e028 'TRAINER V4.EX
E'
[ 478:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e228->0x5e228 'T
RAINER V4.EXE'
[ 478:07b0] :BOX: SetFilePointer(OK): SET 385207(0x5e0b7)/0x57043f, 0x5e228->0
x5e0b7 'TRAINER V4.EXE'
[ 478:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x200 bytes at 0x5e0b7 'TRAINER V4.EX
E'
[ 478:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e0b7 'TRAINER V4.EX
E'
[ 478:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e2b7->0x5e2b7 'T
RAINER V4.EXE'

[ 478:07b0] :BOX: SetFilePointer(OK): SET 774007(0xbcf77)/0x57043f, 0x5e2b7->0


xbcf77 'TRAINER V4.EXE'
[ 478:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x200 bytes at 0xbcf77 'TRAINER V4.EX
E'
[ 483:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0xbcf77 'TRAINER V4.EX
E'
[ 483:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0xbd177->0xbd177 'T
RAINER V4.EXE'
[ 483:07b0] :BOX: SetFilePointer(OK): SET 774056(0xbcfa8)/0x57043f, 0xbd177->0
xbcfa8 'TRAINER V4.EXE'
[ 483:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x200 bytes at 0xbcfa8 'TRAINER V4.EX
E'
[ 483:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0xbcfa8 'TRAINER V4.EX
E'
[ 483:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0xbd1a8->0xbd1a8 'T
RAINER V4.EXE'
[ 483:07b0] :BOX: SetFilePointer(OK): SET 5664206(0x566dce)/0x57043f, 0xbd1a8>0x566dce 'TRAINER V4.EXE'
[ 483:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x200 bytes at 0x566dce 'TRAINER V4.E
XE'
[ 488:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x566dce 'TRAINER V4.E
XE'
[ 488:07b0] :BOX: ReadFile 0x008fede1 <- 0x9000 bytes at 0x566fce 'TRAINER V4.
EXE'
[ 488:07b0] :BOX: ReadFile(OK) 0x9000 wasread 0x9000 offs 0x566fce 'TRAINER V4
.EXE'
[ 488:07b0] :BOX: ReadFile 0x0201d8a0 <- 0x1000 bytes at 0x56ffce 'TRAINER V4.
EXE'
[ 488:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x471 offs 0x56ffce 'TRAINER V4.
EXE'
[ 500:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 534:07b0] :WRAPPER:FindFirstFileW C:\DOCUME~1\CABINA9\CONFIG~1\Temp\vscfnjs
[ 726:07b0] :WRAPPER:LoadLibrary: Secur32.dll, handle is 77fc0000
[ 726:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 735:07b0] :WRAPPER:LoadLibrary: wsock32, handle is 71a50000
[ 737:07b0] :WRAPPER:LoadLibrary: ws2_32, handle is 71a30000
[ 737:07b0] :WRAPPER:LoadLibrary: RASAPI32.DLL
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c8107f0 = Creat
eFileW
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80aedb = LoadL
ibraryW
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80b7dc = GetFi
leAttributesW
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c801a28 = Creat
eFileA
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c801812 = ReadF
ile
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80e4cd = GetMo
duleHandleW
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80ee67 = FindC
lose
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80efca = FindN
extFileW
[ 741:07b0] :LAUNCHER:WRAPPER: RASAPI32.DLL -> KERNEL32.dll!0x7c80ef71 = FindF

irstFileW
[ 741:07b0] :LAUNCHER:WRAPPER:
ibraryA
[ 741:07b0] :LAUNCHER:WRAPPER:
handledExceptionFilter
[ 741:07b0] :LAUNCHER:WRAPPER:
lePointer
[ 741:07b0] :LAUNCHER:WRAPPER:
raryW
[ 741:07b0] :LAUNCHER:WRAPPER:
Address
[ 741:07b0] :LAUNCHER:WRAPPER:
raryA
[ 741:07b0] :LAUNCHER:WRAPPER:
ndle
[ 741:07b0] :LAUNCHER:WRAPPER:
ndledExceptionFilter
[ 741:07b0] :LAUNCHER:WRAPPER:
rary
[ 741:07b0] :LAUNCHER:WRAPPER:
ibraryW
[ 741:07b0] :LAUNCHER:WRAPPER:
leAttributesW
[ 741:07b0] :LAUNCHER:WRAPPER:
lePointer
[ 741:07b0] :LAUNCHER:WRAPPER:
handledExceptionFilter
[ 741:07b0] :LAUNCHER:WRAPPER:
ibraryA
[ 741:07b0] :LAUNCHER:WRAPPER:
ibrary
[ 741:07b0] :LAUNCHER:WRAPPER:
ocAddress
[ 741:07b0] :LAUNCHER:WRAPPER:
eFileW
[ 741:07b0] :LAUNCHER:WRAPPER:
Handle
[ 742:07b0] :LAUNCHER:WRAPPER:
ile
[ 742:07b0] :LAUNCHER:WRAPPER:
duleFileNameA
[ 742:07b0] :LAUNCHER:WRAPPER:
Address
[ 742:07b0] :LAUNCHER:WRAPPER:
raryW
[ 742:07b0] :LAUNCHER:WRAPPER:
leHandleW
[ 742:07b0] :LAUNCHER:WRAPPER:
ndle
[ 742:07b0] :LAUNCHER:WRAPPER:
rary
[ 742:07b0] :LAUNCHER:WRAPPER:
tFileW
[ 742:07b0] :LAUNCHER:WRAPPER:
stFileW
[ 742:07b0] :LAUNCHER:WRAPPER:
ndledExceptionFilter
[ 742:07b0] :LAUNCHER:WRAPPER:
andledExceptionFilter
[ 742:07b0] :LAUNCHER:WRAPPER:

RASAPI32.DLL -> KERNEL32.dll!0x7c801d7b = LoadL


RASAPI32.DLL -> KERNEL32.dll!0x7c8449fd = SetUn
RASAPI32.DLL -> KERNEL32.dll!0x7c810c1e = SetFi
rasman.dll -> KERNEL32.dll!0x7c80aedb = LoadLib
rasman.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
rasman.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
rasman.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
rasman.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
rasman.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
NETAPI32.dll -> KERNEL32.dll!0x7c80aedb = LoadL
NETAPI32.dll -> KERNEL32.dll!0x7c80b7dc = GetFi
NETAPI32.dll -> KERNEL32.dll!0x7c810c1e = SetFi
NETAPI32.dll -> KERNEL32.dll!0x7c8449fd = SetUn
NETAPI32.dll -> KERNEL32.dll!0x7c801d7b = LoadL
NETAPI32.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
NETAPI32.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
NETAPI32.dll -> KERNEL32.dll!0x7c8107f0 = Creat
NETAPI32.dll -> KERNEL32.dll!0x7c809bd7 = Close
NETAPI32.dll -> KERNEL32.dll!0x7c801812 = ReadF
NETAPI32.dll -> KERNEL32.dll!0x7c80b55f = GetMo
TAPI32.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
TAPI32.dll -> KERNEL32.dll!0x7c80aedb = LoadLib
TAPI32.dll -> KERNEL32.dll!0x7c80e4cd = GetModu
TAPI32.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
TAPI32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
TAPI32.dll -> KERNEL32.dll!0x7c80efca = FindNex
TAPI32.dll -> KERNEL32.dll!0x7c80ef71 = FindFir
TAPI32.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
rtutils.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
rtutils.dll -> KERNEL32.dll!0x7c809bd7 = CloseH

andle
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c801a28 = Create
FileA
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[ 742:07b0] :LAUNCHER:WRAPPER: rtutils.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 742:07b0] :WRAPPER:LoadLibrary: RASAPI32.DLL, handle is 76ea0000
[ 742:07b0] :WRAPPER:LoadLibrary: RTUTILS.DLL, handle is 76e40000
[ 743:07b0] :WRAPPER:LoadLibrary: RASMAN.DLL, handle is 76e50000
[ 743:07b0] :WRAPPER:LoadLibrary: secur32.dll, handle is 77fc0000
[ 744:07b0] :WRAPPER: Search msapsspc.dll in NULL
[ 744:07b0] :WRAPPER: Search schannel.dll in NULL
[ 744:07b0] :WRAPPER: Search digest.dll in NULL
[ 744:07b0] :WRAPPER: Search msnsspc.dll in NULL
[ 744:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msv1_0.dll
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c8107f0 = Creat
eFileW
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c801a28 = Creat
eFileA
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 746:07b0] :LAUNCHER:WRAPPER: iphlpapi.dll -> KERNEL32.dll!0x7c801d7b = LoadL
ibraryA
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c8449fd = SetUnhandledExceptionFilter
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c80e4cd = GetModuleHandleW
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c801d7b = LoadLibraryA
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c80aedb = LoadLibraryW
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c80ae30 = GetProcAddress
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c80ac6e = FreeLibrary
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c8107f0 = CreateFileW
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c810c1e = SetFilePointer
[ 746:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msv1_0.dll -> KERNEL32.dll!
0x7c809bd7 = CloseHandle
[ 746:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msv1_0.dll, handle is 77
c40000

[ 753:07b0] :WRAPPER:LoadLibrary: sensapi.dll


[ 753:07b0] :LAUNCHER:WRAPPER: sensapi.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[ 753:07b0] :LAUNCHER:WRAPPER: sensapi.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 753:07b0] :LAUNCHER:WRAPPER: sensapi.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[ 753:07b0] :WRAPPER:LoadLibrary: sensapi.dll, handle is 72250000
[ 755:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 755:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 755:07b0] :WRAPPER:LoadLibrary: SHELL32.dll, handle is 7e6a0000
[ 755:07b0] :WRAPPER:LoadLibrary: USERENV.dll, handle is 76630000
[ 757:07b0] :WRAPPER:LoadLibrary: netapi32.dll, handle is 597f0000
[ 757:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 758:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 758:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 758:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 758:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 760:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 761:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 761:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 761:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 761:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 761:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 761:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 762:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 763:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 764:07b0] :WRAPPER:LoadLibrary: urlmon.dll
[ 768:07b0] :WRAPPER:LoadLibrary: comctl32.dll, handle is 773a0000
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c81cafa = ExitPro
cess
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVi
ewOfFile
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c8094ee = CreateF
ileMappingA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80b995 = MapView
OfFile
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c834ec9 = FindNex
tFileA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c8217d2 = SearchP
athA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c83644c = GetPriv
ateProfileIntA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c832b6e = GetPriv
ateProfileStringA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c813869 = FindFir
stFileA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c8115cc = GetFile
AttributesA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c801a28 = CreateF
ileA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c810c1e = SetFile
Pointer
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c801812 = ReadFil

e
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c810b07 = GetFile
Size
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80ee67 = FindClo
se
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c801d53 = LoadLib
raryExA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80b55f = GetModu
leFileNameA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
raryA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80b731 = GetModu
leHandleA
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c80aedb = LoadLib
raryW
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> ole32.dll!0x774d057e = CoCreateIn
stance
[ 769:07b0] :LAUNCHER:WRAPPER: urlmon.dll -> ole32.dll!0x774e56c5 = CoGetClass
Object
[ 769:07b0] :WRAPPER:LoadLibrary: urlmon.dll, handle is 7df20000
[ 771:07b0] :WRAPPER:LoadLibrary: WININET.dll, handle is 77180000
[ 771:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\mswsock.dll
[ 771:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c801812 = ReadFile
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c801a28 = CreateFileA
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c8449fd = SetUnhandledExceptionFilter
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c8094ee = CreateFileMappingA
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c80b995 = MapViewOfFile
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c80ba04 = UnmapViewOfFile
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c80ae30 = GetProcAddress
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c801d7b = LoadLibraryA
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c80b55f = GetModuleFileNameA
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c80aedb = LoadLibraryW
[ 772:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\mswsock.dll -> KERNEL32.dll
!0x7c809bd7 = CloseHandle
[ 772:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\mswsock.dll, handle is 7
19d0000
[ 772:07b0] :WRAPPER:LoadLibrary: DNSAPI.dll
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c801af5 = LoadLib
raryExW
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa

ndle
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c80b55f = GetModu
leFileNameA
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c80b731 = GetModu
leHandleA
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
raryA
[ 773:07b0] :LAUNCHER:WRAPPER: DNSAPI.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[ 773:07b0] :WRAPPER:LoadLibrary: DNSAPI.dll, handle is 76ee0000
[ 773:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\winrnr.dll
[ 774:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\winrnr.dll -> KERNEL32.dll!
0x7c8449fd = SetUnhandledExceptionFilter
[ 774:07b0] :LAUNCHER:WRAPPER: WLDAP32.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 774:07b0] :LAUNCHER:WRAPPER: WLDAP32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 774:07b0] :LAUNCHER:WRAPPER: WLDAP32.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 774:07b0] :LAUNCHER:WRAPPER: WLDAP32.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[ 774:07b0] :LAUNCHER:WRAPPER: WLDAP32.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 774:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\winrnr.dll, handle is 76
f70000
[ 774:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\mswsock.dll, handle is 7
19d0000
[ 775:07b0] :WRAPPER:LoadLibrary: rasadhlp.dll
[ 775:07b0] :LAUNCHER:WRAPPER: rasadhlp.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[ 775:07b0] :LAUNCHER:WRAPPER: rasadhlp.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 775:07b0] :LAUNCHER:WRAPPER: rasadhlp.dll -> KERNEL32.dll!0x7c80aedb = LoadL
ibraryW
[ 775:07b0] :LAUNCHER:WRAPPER: rasadhlp.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[ 775:07b0] :LAUNCHER:WRAPPER: rasadhlp.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 775:07b0] :WRAPPER:LoadLibrary: rasadhlp.dll, handle is 76f80000
[ 775:07b0] :WRAPPER:LoadLibrary: iphlpapi.dll, handle is 76d20000
[ 776:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mswsock.dll, handle is 7
19d0000
[ 776:07b0] :WRAPPER:LoadLibrary: hnetcfg.dll
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
uleHandleW
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c80aedb = LoadLi

braryW
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[ 776:07b0] :LAUNCHER:WRAPPER: hnetcfg.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 776:07b0] :WRAPPER:LoadLibrary: hnetcfg.dll, handle is 66740000
[ 776:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\mswsock.dll, handle is 7
19d0000
[ 776:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\wshtcpip.dll
[ 777:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\System32\wshtcpip.dll -> KERNEL32.dl
l!0x7c8449fd = SetUnhandledExceptionFilter
[ 777:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\wshtcpip.dll, handle is
71a10000
[ 1501:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5
7043f)
[ 1501:07b0] :BOX: ReadFile 0x008fecb4 <- 0x10000 bytes at 0x0 'TRAINER V4.EXE'
[ 1508:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x0 'TRAINER V4.EX
E'
[ 1509:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x10000->0x10000 'T
RAINER V4.EXE'
[ 1509:07b0] :BOX: SetFilePointer(OK): SET 65516(0xffec)/0x57043f, 0x10000->0xf
fec 'TRAINER V4.EXE'
[ 1509:07b0] :BOX: ReadFile 0x008fecb4 <- 0x10000 bytes at 0xffec 'TRAINER V4.E
XE'
[ 1514:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0xffec 'TRAINER V4
.EXE'
[ 1515:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x1ffec->0x1ffec 'T
RAINER V4.EXE'
[ 1515:07b0] :BOX: SetFilePointer(OK): SET 131032(0x1ffd8)/0x57043f, 0x1ffec->0
x1ffd8 'TRAINER V4.EXE'
[ 1515:07b0] :BOX: ReadFile 0x008fecb4 <- 0x10000 bytes at 0x1ffd8 'TRAINER V4.
EXE'
[ 1520:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x1ffd8 'TRAINER V
4.EXE'
[ 1520:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x2ffd8->0x2ffd8 'T
RAINER V4.EXE'
[ 1520:07b0] :BOX: SetFilePointer(OK): SET 196548(0x2ffc4)/0x57043f, 0x2ffd8->0
x2ffc4 'TRAINER V4.EXE'
[ 1520:07b0] :BOX: ReadFile 0x008fecb4 <- 0x10000 bytes at 0x2ffc4 'TRAINER V4.
EXE'
[ 1528:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x2ffc4 'TRAINER V
4.EXE'
[ 1528:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x3ffc4->0x3ffc4 'T
RAINER V4.EXE'
[ 1528:07b0] :BOX: SetFilePointer(OK): SET 262064(0x3ffb0)/0x57043f, 0x3ffc4->0
x3ffb0 'TRAINER V4.EXE'
[ 1528:07b0] :BOX: ReadFile 0x008fecb4 <- 0x10000 bytes at 0x3ffb0 'TRAINER V4.
EXE'
[ 1533:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x3ffb0 'TRAINER V
4.EXE'
[ 1533:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x4ffb0->0x4ffb0 'T
RAINER V4.EXE'
[ 1533:07b0] :BOX: SetFilePointer(OK): SET 327580(0x4ff9c)/0x57043f, 0x4ffb0->0
x4ff9c 'TRAINER V4.EXE'
[ 1533:07b0] :BOX: ReadFile 0x008fecb4 <- 0x10000 bytes at 0x4ff9c 'TRAINER V4.
EXE'
[ 1544:07b0] :BOX: ReadFile(OK) 0x10000 wasread 0x10000 offs 0x4ff9c 'TRAINER V
4.EXE'
[ 1544:07b0] :BOX: SetFilePointer(OK): SET 385044(0x5e014)/0x57043f, 0x5ff9c->0
x5e014 'TRAINER V4.EXE'

[ 1544:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x5e014 'TRAINER V4.E
XE'
[ 1544:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x5e014 'TRAINER V4.
EXE'
[ 1544:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5f014->0x5f014 'T
RAINER V4.EXE'
[ 1544:07b0] :BOX: SetFilePointer(OK): SET 385064(0x5e028)/0x57043f, 0x5f014->0
x5e028 'TRAINER V4.EXE'
[ 1544:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x200 bytes at 0x5e028 'TRAINER V4.EX
E'
[ 1544:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e028 'TRAINER V4.EX
E'
[ 1544:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e228->0x5e228 'T
RAINER V4.EXE'
[ 1544:07b0] :BOX: SetFilePointer(OK): SET 385207(0x5e0b7)/0x57043f, 0x5e228->0
x5e0b7 'TRAINER V4.EXE'
[ 1544:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x200 bytes at 0x5e0b7 'TRAINER V4.EX
E'
[ 1544:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0x5e0b7 'TRAINER V4.EX
E'
[ 1544:07b0] :BOX: SetFilePointer(OK): CUR 0(0x0)/0x57043f, 0x5e2b7->0x5e2b7 'T
RAINER V4.EXE'
[ 1544:07b0] :BOX: SetFilePointer(OK): SET 774007(0xbcf77)/0x57043f, 0x5e2b7->0
xbcf77 'TRAINER V4.EXE'
[ 1544:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x200 bytes at 0xbcf77 'TRAINER V4.EX
E'
[ 1550:07b0] :BOX: ReadFile(OK) 0x200 wasread 0x200 offs 0xbcf77 'TRAINER V4.EX
E'
[ 1550:07b0] :BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0xbd177 'TRAINER V4.E
XE'
[ 1555:07b0] :BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0xbd177 'TRAINER V4.
EXE'
[ 1555:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0xcc177 'TRAINER V4.E
XE'
[ 1555:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0xcc177 'TRAINER V4.
EXE'
[ 1559:07b0] :BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0xcd177 'TRAINER V4.E
XE'
[ 1565:07b0] :BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0xcd177 'TRAINER V4.
EXE'
[ 1565:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0xdc177 'TRAINER V4.E
XE'
[ 1565:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0xdc177 'TRAINER V4.
EXE'
[ 1569:07b0] :BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0xdd177 'TRAINER V4.E
XE'
[ 1574:07b0] :BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0xdd177 'TRAINER V4.
EXE'
[ 1574:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0xec177 'TRAINER V4.E
XE'
[ 1574:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0xec177 'TRAINER V4.
EXE'
[ 1578:07b0] :BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0xed177 'TRAINER V4.E
XE'
[ 1583:07b0] :BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0xed177 'TRAINER V4.
EXE'
[ 1583:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0xfc177 'TRAINER V4.E
XE'
[ 1583:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0xfc177 'TRAINER V4.
EXE'

[ 1587:07b0]
XE'
[ 1592:07b0]
EXE'
[ 1592:07b0]
EXE'
[ 1592:07b0]
.EXE'
[ 1596:07b0]
EXE'
[ 1601:07b0]
.EXE'
[ 1601:07b0]
EXE'
[ 1601:07b0]
.EXE'
[ 1605:07b0]
EXE'
[ 1610:07b0]
.EXE'
[ 1610:07b0]
EXE'
[ 1610:07b0]
.EXE'
[ 1614:07b0]
EXE'
[ 1619:07b0]
.EXE'
[ 1619:07b0]
EXE'
[ 1619:07b0]
.EXE'
[ 1623:07b0]
EXE'
[ 1629:07b0]
.EXE'
[ 1629:07b0]
EXE'
[ 1629:07b0]
.EXE'
[ 1633:07b0]
EXE'
[ 1638:07b0]
.EXE'
[ 1638:07b0]
EXE'
[ 1638:07b0]
.EXE'
[ 1642:07b0]
EXE'
[ 1647:07b0]
.EXE'
[ 1647:07b0]
EXE'
[ 1647:07b0]
.EXE'
[ 1651:07b0]
EXE'
[ 1656:07b0]
.EXE'

:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0xfd177 'TRAINER V4.E


:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0xfd177 'TRAINER V4.
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x10c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x10c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x10d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x10d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x11c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x11c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x11d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x11d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x12c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x12c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x12d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x12d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x13c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x13c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x13d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x13d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x14c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x14c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x14d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x14d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x15c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x15c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x15d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x15d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x16c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x16c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x16d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x16d177 'TRAINER V4

[ 1656:07b0]
EXE'
[ 1656:07b0]
.EXE'
[ 1660:07b0]
EXE'
[ 1665:07b0]
.EXE'
[ 1665:07b0]
EXE'
[ 1665:07b0]
.EXE'
[ 1669:07b0]
EXE'
[ 1674:07b0]
.EXE'
[ 1674:07b0]
EXE'
[ 1674:07b0]
.EXE'
[ 1678:07b0]
EXE'
[ 1683:07b0]
.EXE'
[ 1683:07b0]
EXE'
[ 1683:07b0]
.EXE'
[ 1687:07b0]
EXE'
[ 1692:07b0]
.EXE'
[ 1692:07b0]
EXE'
[ 1692:07b0]
.EXE'
[ 1696:07b0]
EXE'
[ 1701:07b0]
.EXE'
[ 1701:07b0]
EXE'
[ 1701:07b0]
.EXE'
[ 1705:07b0]
EXE'
[ 1710:07b0]
.EXE'
[ 1710:07b0]
EXE'
[ 1710:07b0]
.EXE'
[ 1714:07b0]
EXE'
[ 1719:07b0]
.EXE'
[ 1719:07b0]
EXE'
[ 1719:07b0]
.EXE'

:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x17c177 'TRAINER V4.


:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x17c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x17d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x17d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x18c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x18c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x18d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x18d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x19c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x19c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x19d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x19d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x1ac177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x1ac177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x1ad177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x1ad177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x1bc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x1bc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x1bd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x1bd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x1cc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x1cc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x1cd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x1cd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x1dc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x1dc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x1dd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x1dd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x1ec177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x1ec177 'TRAINER V4

[ 1723:07b0]
EXE'
[ 1728:07b0]
.EXE'
[ 1728:07b0]
EXE'
[ 1728:07b0]
.EXE'
[ 1732:07b0]
EXE'
[ 1737:07b0]
.EXE'
[ 1737:07b0]
EXE'
[ 1737:07b0]
.EXE'
[ 1741:07b0]
EXE'
[ 1746:07b0]
.EXE'
[ 1746:07b0]
EXE'
[ 1746:07b0]
.EXE'
[ 1750:07b0]
EXE'
[ 1755:07b0]
.EXE'
[ 1755:07b0]
EXE'
[ 1755:07b0]
.EXE'
[ 1759:07b0]
EXE'
[ 1764:07b0]
.EXE'
[ 1764:07b0]
EXE'
[ 1764:07b0]
.EXE'
[ 1768:07b0]
EXE'
[ 1773:07b0]
.EXE'
[ 1773:07b0]
EXE'
[ 1773:07b0]
.EXE'
[ 1777:07b0]
EXE'
[ 1782:07b0]
.EXE'
[ 1782:07b0]
EXE'
[ 1782:07b0]
.EXE'
[ 1786:07b0]
EXE'
[ 1791:07b0]
.EXE'

:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x1ed177 'TRAINER V4.


:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x1ed177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x1fc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x1fc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x1fd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x1fd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x20c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x20c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x20d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x20d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x21c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x21c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x21d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x21d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x22c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x22c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x22d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x22d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x23c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x23c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x23d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x23d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x24c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x24c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x24d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x24d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x25c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x25c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x25d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x25d177 'TRAINER V4

[ 1791:07b0]
EXE'
[ 1791:07b0]
.EXE'
[ 1794:07b0]
EXE'
[ 1800:07b0]
.EXE'
[ 1800:07b0]
EXE'
[ 1800:07b0]
.EXE'
[ 1804:07b0]
EXE'
[ 1809:07b0]
.EXE'
[ 1809:07b0]
EXE'
[ 1809:07b0]
.EXE'
[ 1813:07b0]
EXE'
[ 1818:07b0]
.EXE'
[ 1818:07b0]
EXE'
[ 1818:07b0]
.EXE'
[ 1822:07b0]
EXE'
[ 1827:07b0]
.EXE'
[ 1827:07b0]
EXE'
[ 1827:07b0]
.EXE'
[ 1831:07b0]
EXE'
[ 1836:07b0]
.EXE'
[ 1836:07b0]
EXE'
[ 1836:07b0]
.EXE'
[ 1840:07b0]
EXE'
[ 1845:07b0]
.EXE'
[ 1845:07b0]
EXE'
[ 1845:07b0]
.EXE'
[ 1849:07b0]
EXE'
[ 1854:07b0]
.EXE'
[ 1854:07b0]
EXE'
[ 1854:07b0]
.EXE'

:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x26c177 'TRAINER V4.


:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x26c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x26d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x26d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x27c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x27c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x27d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x27d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x28c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x28c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x28d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x28d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x29c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x29c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x29d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x29d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x2ac177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x2ac177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x2ad177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x2ad177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x2bc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x2bc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x2bd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x2bd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x2cc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x2cc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x2cd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x2cd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x2dc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x2dc177 'TRAINER V4

[ 1858:07b0]
EXE'
[ 1863:07b0]
.EXE'
[ 1863:07b0]
EXE'
[ 1863:07b0]
.EXE'
[ 1867:07b0]
EXE'
[ 1872:07b0]
.EXE'
[ 1872:07b0]
EXE'
[ 1872:07b0]
.EXE'
[ 1876:07b0]
EXE'
[ 1881:07b0]
.EXE'
[ 1881:07b0]
EXE'
[ 1881:07b0]
.EXE'
[ 1884:07b0]
EXE'
[ 1889:07b0]
.EXE'
[ 1889:07b0]
EXE'
[ 1889:07b0]
.EXE'
[ 1893:07b0]
EXE'
[ 1898:07b0]
.EXE'
[ 1898:07b0]
EXE'
[ 1898:07b0]
.EXE'
[ 1902:07b0]
EXE'
[ 1907:07b0]
.EXE'
[ 1907:07b0]
EXE'
[ 1907:07b0]
.EXE'
[ 1911:07b0]
EXE'
[ 1916:07b0]
.EXE'
[ 1916:07b0]
EXE'
[ 1916:07b0]
.EXE'
[ 1920:07b0]
EXE'
[ 1925:07b0]
.EXE'

:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x2dd177 'TRAINER V4.


:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x2dd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x2ec177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x2ec177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x2ed177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x2ed177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x2fc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x2fc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x2fd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x2fd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x30c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x30c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x30d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x30d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x31c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x31c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x31d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x31d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x32c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x32c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x32d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x32d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x33c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x33c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x33d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x33d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x34c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x34c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x34d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x34d177 'TRAINER V4

[ 1925:07b0]
EXE'
[ 1925:07b0]
.EXE'
[ 1929:07b0]
EXE'
[ 1934:07b0]
.EXE'
[ 1934:07b0]
EXE'
[ 1934:07b0]
.EXE'
[ 1938:07b0]
EXE'
[ 1943:07b0]
.EXE'
[ 1943:07b0]
EXE'
[ 1943:07b0]
.EXE'
[ 1947:07b0]
EXE'
[ 1952:07b0]
.EXE'
[ 1952:07b0]
EXE'
[ 1952:07b0]
.EXE'
[ 1956:07b0]
EXE'
[ 1961:07b0]
.EXE'
[ 1961:07b0]
EXE'
[ 1961:07b0]
.EXE'
[ 1965:07b0]
EXE'
[ 1970:07b0]
.EXE'
[ 1970:07b0]
EXE'
[ 1970:07b0]
.EXE'
[ 1974:07b0]
EXE'
[ 1979:07b0]
.EXE'
[ 1979:07b0]
EXE'
[ 1979:07b0]
.EXE'
[ 1983:07b0]
EXE'
[ 1988:07b0]
.EXE'
[ 1988:07b0]
EXE'
[ 1988:07b0]
.EXE'

:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x35c177 'TRAINER V4.


:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x35c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x35d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x35d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x36c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x36c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x36d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x36d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x37c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x37c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x37d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x37d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x38c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x38c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x38d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x38d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x39c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x39c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x39d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x39d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x3ac177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x3ac177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x3ad177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x3ad177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x3bc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x3bc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x3bd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x3bd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x3cc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x3cc177 'TRAINER V4

[ 1992:07b0]
EXE'
[ 1998:07b0]
.EXE'
[ 1998:07b0]
EXE'
[ 1998:07b0]
.EXE'
[ 2001:07b0]
EXE'
[ 2007:07b0]
.EXE'
[ 2007:07b0]
EXE'
[ 2007:07b0]
.EXE'
[ 2011:07b0]
EXE'
[ 2016:07b0]
.EXE'
[ 2016:07b0]
EXE'
[ 2016:07b0]
.EXE'
[ 2020:07b0]
EXE'
[ 2025:07b0]
.EXE'
[ 2025:07b0]
EXE'
[ 2025:07b0]
.EXE'
[ 2029:07b0]
EXE'
[ 2034:07b0]
.EXE'
[ 2034:07b0]
EXE'
[ 2034:07b0]
.EXE'
[ 2038:07b0]
EXE'
[ 2043:07b0]
.EXE'
[ 2043:07b0]
EXE'
[ 2043:07b0]
.EXE'
[ 2047:07b0]
EXE'
[ 2051:07b0]
.EXE'
[ 2052:07b0]
EXE'
[ 2052:07b0]
.EXE'
[ 2055:07b0]
EXE'
[ 2061:07b0]
.EXE'

:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x3cd177 'TRAINER V4.


:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x3cd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x3dc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x3dc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x3dd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x3dd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x3ec177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x3ec177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x3ed177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x3ed177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x3fc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x3fc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x3fd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x3fd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x40c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x40c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x40d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x40d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x41c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x41c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x41d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x41d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x42c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x42c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x42d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x42d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x43c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x43c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x43d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x43d177 'TRAINER V4

[ 2061:07b0]
EXE'
[ 2061:07b0]
.EXE'
[ 2064:07b0]
EXE'
[ 2069:07b0]
.EXE'
[ 2069:07b0]
EXE'
[ 2069:07b0]
.EXE'
[ 2073:07b0]
EXE'
[ 2078:07b0]
.EXE'
[ 2078:07b0]
EXE'
[ 2078:07b0]
.EXE'
[ 2082:07b0]
EXE'
[ 2087:07b0]
.EXE'
[ 2087:07b0]
EXE'
[ 2087:07b0]
.EXE'
[ 2090:07b0]
EXE'
[ 2095:07b0]
.EXE'
[ 2095:07b0]
EXE'
[ 2095:07b0]
.EXE'
[ 2099:07b0]
EXE'
[ 2104:07b0]
.EXE'
[ 2104:07b0]
EXE'
[ 2104:07b0]
.EXE'
[ 2108:07b0]
EXE'
[ 2113:07b0]
.EXE'
[ 2113:07b0]
EXE'
[ 2113:07b0]
.EXE'
[ 2117:07b0]
EXE'
[ 2122:07b0]
.EXE'
[ 2122:07b0]
EXE'
[ 2122:07b0]
.EXE'

:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x44c177 'TRAINER V4.


:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x44c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x44d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x44d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x45c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x45c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x45d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x45d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x46c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x46c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x46d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x46d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x47c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x47c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x47d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x47d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x48c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x48c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x48d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x48d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x49c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x49c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x49d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x49d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x4ac177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x4ac177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x4ad177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x4ad177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x4bc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x4bc177 'TRAINER V4

[ 2126:07b0]
EXE'
[ 2131:07b0]
.EXE'
[ 2131:07b0]
EXE'
[ 2131:07b0]
.EXE'
[ 2135:07b0]
EXE'
[ 2140:07b0]
.EXE'
[ 2140:07b0]
EXE'
[ 2140:07b0]
.EXE'
[ 2143:07b0]
EXE'
[ 2149:07b0]
.EXE'
[ 2149:07b0]
EXE'
[ 2149:07b0]
.EXE'
[ 2152:07b0]
EXE'
[ 2157:07b0]
.EXE'
[ 2157:07b0]
EXE'
[ 2158:07b0]
.EXE'
[ 2161:07b0]
EXE'
[ 2166:07b0]
.EXE'
[ 2166:07b0]
EXE'
[ 2166:07b0]
.EXE'
[ 2170:07b0]
EXE'
[ 2175:07b0]
.EXE'
[ 2175:07b0]
EXE'
[ 2175:07b0]
.EXE'
[ 2179:07b0]
EXE'
[ 2184:07b0]
.EXE'
[ 2184:07b0]
EXE'
[ 2184:07b0]
.EXE'
[ 2188:07b0]
EXE'
[ 2193:07b0]
.EXE'

:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x4bd177 'TRAINER V4.


:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x4bd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x4cc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x4cc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x4cd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x4cd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x4dc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x4dc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x4dd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x4dd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x4ec177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x4ec177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x4ed177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x4ed177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x4fc177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x4fc177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x4fd177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x4fd177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x50c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x50c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x50d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x50d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x51c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x51c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x51d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x51d177 'TRAINER V4
:BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x52c177 'TRAINER V4.
:BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x52c177 'TRAINER V4
:BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x52d177 'TRAINER V4.
:BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x52d177 'TRAINER V4

[ 2193:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x53c177 'TRAINER V4.
EXE'
[ 2193:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x53c177 'TRAINER V4
.EXE'
[ 2197:07b0] :BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x53d177 'TRAINER V4.
EXE'
[ 2202:07b0] :BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x53d177 'TRAINER V4
.EXE'
[ 2202:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x54c177 'TRAINER V4.
EXE'
[ 2202:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x54c177 'TRAINER V4
.EXE'
[ 2206:07b0] :BOX: ReadFile 0x008ff03b <- 0xf000 bytes at 0x54d177 'TRAINER V4.
EXE'
[ 2211:07b0] :BOX: ReadFile(OK) 0xf000 wasread 0xf000 offs 0x54d177 'TRAINER V4
.EXE'
[ 2211:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x55c177 'TRAINER V4.
EXE'
[ 2211:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x55c177 'TRAINER V4
.EXE'
[ 2215:07b0] :BOX: ReadFile 0x008ff03b <- 0x9000 bytes at 0x55d177 'TRAINER V4.
EXE'
[ 2220:07b0] :BOX: ReadFile(OK) 0x9000 wasread 0x9000 offs 0x55d177 'TRAINER V4
.EXE'
[ 2220:07b0] :BOX: ReadFile 0x022d1ee8 <- 0x1000 bytes at 0x566177 'TRAINER V4.
EXE'
[ 2220:07b0] :BOX: ReadFile(OK) 0x1000 wasread 0x1000 offs 0x566177 'TRAINER V4
.EXE'
[ 2232:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 2234:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2235:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2235:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c80aedb = LoadLib
raryW
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c80b995 = MapView
OfFile
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c809420 = CreateF
ileMappingW
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c8107f0 = CreateF
ileW
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c80ba04 = UnmapVi
ewOfFile
[ 2235:0ca0] :LAUNCHER:WRAPPER: wdmaud.drv -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[ 2235:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2235:0ca0] :WRAPPER:LoadLibrary: setupapi.dll, handle is 778f0000
[ 2236:0ca0] :WRAPPER:LoadLibrary: WINTRUST.dll
[ 2236:0ca0] :LAUNCHER:WRAPPER: IMAGEHLP.dll -> KERNEL32.dll!0x7c8115cc = GetFi
leAttributesA
[ 2236:0ca0] :LAUNCHER:WRAPPER: IMAGEHLP.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 2236:0ca0] :LAUNCHER:WRAPPER: IMAGEHLP.dll -> KERNEL32.dll!0x7c80b731 = GetMo
duleHandleA
[ 2236:0ca0] :LAUNCHER:WRAPPER: IMAGEHLP.dll -> KERNEL32.dll!0x7c809bd7 = Close

Handle
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ViewOfFile
[ 2236:0ca0] :LAUNCHER:WRAPPER:
eFileMappingA
[ 2236:0ca0] :LAUNCHER:WRAPPER:
leSize
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ewOfFile
[ 2236:0ca0] :LAUNCHER:WRAPPER:
eFileA
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ibraryA
[ 2236:0ca0] :LAUNCHER:WRAPPER:
duleFileNameA
[ 2236:0ca0] :LAUNCHER:WRAPPER:
lePointer
[ 2236:0ca0] :LAUNCHER:WRAPPER:
hPathA
[ 2236:0ca0] :LAUNCHER:WRAPPER:
handledExceptionFilter
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ibrary
[ 2236:0ca0] :LAUNCHER:WRAPPER:
eFileW
[ 2236:0ca0] :LAUNCHER:WRAPPER:
leAttributesW
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ibrary
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ocAddress
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ibraryA
[ 2236:0ca0] :LAUNCHER:WRAPPER:
ile
[ 2236:0ca0] :LAUNCHER:WRAPPER:
lePointer
[ 2236:0ca0] :LAUNCHER:WRAPPER:
handledExceptionFilter
[ 2237:0ca0] :LAUNCHER:WRAPPER:
duleHandleA
[ 2237:0ca0] :LAUNCHER:WRAPPER:
leSize
[ 2237:0ca0] :LAUNCHER:WRAPPER:
ViewOfFile
[ 2237:0ca0] :LAUNCHER:WRAPPER:
ewOfFile
[ 2237:0ca0] :LAUNCHER:WRAPPER:
eFileMappingA
[ 2237:0ca0] :LAUNCHER:WRAPPER:
lose
[ 2237:0ca0] :LAUNCHER:WRAPPER:
eFileA
[ 2237:0ca0] :LAUNCHER:WRAPPER:
eFileW
[ 2237:0ca0] :LAUNCHER:WRAPPER:
leAttributesA
[ 2237:0ca0] :LAUNCHER:WRAPPER:
leAttributesW
[ 2237:0ca0] :LAUNCHER:WRAPPER:

IMAGEHLP.dll -> KERNEL32.dll!0x7c80ba04 = Unmap


IMAGEHLP.dll -> KERNEL32.dll!0x7c8094ee = Creat
IMAGEHLP.dll -> KERNEL32.dll!0x7c810b07 = GetFi
IMAGEHLP.dll -> KERNEL32.dll!0x7c80b995 = MapVi
IMAGEHLP.dll -> KERNEL32.dll!0x7c801a28 = Creat
IMAGEHLP.dll -> KERNEL32.dll!0x7c801d7b = LoadL
IMAGEHLP.dll -> KERNEL32.dll!0x7c80b55f = GetMo
IMAGEHLP.dll -> KERNEL32.dll!0x7c810c1e = SetFi
IMAGEHLP.dll -> KERNEL32.dll!0x7c8217d2 = Searc
IMAGEHLP.dll -> KERNEL32.dll!0x7c8449fd = SetUn
IMAGEHLP.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
IMAGEHLP.dll -> KERNEL32.dll!0x7c8107f0 = Creat
IMAGEHLP.dll -> KERNEL32.dll!0x7c80b7dc = GetFi
WINTRUST.dll -> KERNEL32.dll!0x7c80ac6e = FreeL
WINTRUST.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
WINTRUST.dll -> KERNEL32.dll!0x7c801d7b = LoadL
WINTRUST.dll -> KERNEL32.dll!0x7c801812 = ReadF
WINTRUST.dll -> KERNEL32.dll!0x7c810c1e = SetFi
WINTRUST.dll -> KERNEL32.dll!0x7c8449fd = SetUn
WINTRUST.dll -> KERNEL32.dll!0x7c80b731 = GetMo
WINTRUST.dll -> KERNEL32.dll!0x7c810b07 = GetFi
WINTRUST.dll -> KERNEL32.dll!0x7c80ba04 = Unmap
WINTRUST.dll -> KERNEL32.dll!0x7c80b995 = MapVi
WINTRUST.dll -> KERNEL32.dll!0x7c8094ee = Creat
WINTRUST.dll -> KERNEL32.dll!0x7c80ee67 = FindC
WINTRUST.dll -> KERNEL32.dll!0x7c801a28 = Creat
WINTRUST.dll -> KERNEL32.dll!0x7c8107f0 = Creat
WINTRUST.dll -> KERNEL32.dll!0x7c8115cc = GetFi
WINTRUST.dll -> KERNEL32.dll!0x7c80b7dc = GetFi
WINTRUST.dll -> KERNEL32.dll!0x7c80aedb = LoadL

ibraryW
[ 2237:0ca0] :LAUNCHER:WRAPPER: WINTRUST.dll -> KERNEL32.dll!0x7c813869 = FindF
irstFileA
[ 2237:0ca0] :LAUNCHER:WRAPPER: WINTRUST.dll -> KERNEL32.dll!0x7c80ef71 = FindF
irstFileW
[ 2237:0ca0] :LAUNCHER:WRAPPER: WINTRUST.dll -> KERNEL32.dll!0x7c834ec9 = FindN
extFileA
[ 2237:0ca0] :LAUNCHER:WRAPPER: WINTRUST.dll -> KERNEL32.dll!0x7c80efca = FindN
extFileW
[ 2237:0ca0] :LAUNCHER:WRAPPER: WINTRUST.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 2237:0ca0] :WRAPPER:LoadLibrary: WINTRUST.dll, handle is 76bf0000
[ 2237:0ca0] :WRAPPER:FreeLibrary:778f0000, 'C:\WINDOWS\system32\SETUPAPI.dll'
[ 2239:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2239:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2239:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2242:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2242:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2243:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2243:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2244:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2244:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2245:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2245:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2246:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2249:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2249:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2250:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2252:0ca0] :WRAPPER:FreeLibrary:72ca0000, 'C:\WINDOWS\system32\wdmaud.drv'
[ 2253:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2253:0ca0] :WRAPPER: Search wdmaud.drv in NULL
[ 2253:0ca0] :WRAPPER:LoadLibrary: wdmaud.drv, handle is 72ca0000
[ 2256:0ca0] :WRAPPER:FreeLibrary:72ca0000, 'C:\WINDOWS\system32\wdmaud.drv'
[ 2259:0ca0] :WRAPPER:LoadLibrary: msacm32.drv
[ 2260:0ca0] :LAUNCHER:WRAPPER: msacm32.drv -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c809420 = Create
FileMappingW
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
uleHandleW
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 2260:0ca0] :LAUNCHER:WRAPPER: MSACM32.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 2261:0ca0] :WRAPPER:LoadLibrary: msacm32.drv, handle is 72c90000
[ 2261:0ca0] :WRAPPER:LoadLibrary: msacm32.drv, handle is 72c90000
[ 2261:0ca0] :WRAPPER:FreeLibrary:72c90000, 'C:\WINDOWS\system32\msacm32.drv'
[ 2261:0ca0] :WRAPPER:LoadLibrary: msacm32.drv, handle is 72c90000
[ 2261:0ca0] :WRAPPER:FreeLibrary:72c90000, 'C:\WINDOWS\system32\msacm32.drv'
[ 2261:0ca0] :WRAPPER:LoadLibrary: msacm32.drv, handle is 72c90000
[ 2261:0ca0] :WRAPPER:FreeLibrary:72c90000, 'C:\WINDOWS\system32\msacm32.drv'
[ 2262:0ca0] :WRAPPER:LoadLibrary: msacm32.drv, handle is 72c90000
[ 2262:0ca0] :WRAPPER:FreeLibrary:72c90000, 'C:\WINDOWS\system32\msacm32.drv'
[ 2263:0ca0] :WRAPPER:LoadLibrary: msacm32.drv, handle is 72c90000

[ 2266:0ca0] :WRAPPER:LoadLibrary: midimap.dll


[ 2266:0ca0] :LAUNCHER:WRAPPER: midimap.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 2266:0ca0] :LAUNCHER:WRAPPER: midimap.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 2266:0ca0] :WRAPPER:LoadLibrary: midimap.dll, handle is 77ba0000
[ 2266:0ca0] :WRAPPER:LoadLibrary: midimap.dll, handle is 77ba0000
[ 2266:0ca0] :WRAPPER:LoadLibrary: midimap.dll, handle is 77ba0000
[ 2266:0ca0] :WRAPPER:FreeLibrary:77ba0000, 'C:\WINDOWS\system32\midimap.dll'
[ 2266:0ca0] :WRAPPER:FreeLibrary:77ba0000, 'C:\WINDOWS\system32\midimap.dll'
[ 2267:0ca0] :WRAPPER:LoadLibrary: midimap.dll, handle is 77ba0000
[ 2267:0ca0] :WRAPPER:FreeLibrary:77ba0000, 'C:\WINDOWS\system32\midimap.dll'
[ 2267:07b0] :WRAPPER: Search mciqtz32.dll in NULL
[ 2267:07b0] :WRAPPER:LoadLibrary: mciqtz32.dll
[ 2268:07b0] :LAUNCHER:WRAPPER: mciqtz32.dll -> KERNEL32.dll!0x7c80e4cd = GetMo
duleHandleW
[ 2268:07b0] :LAUNCHER:WRAPPER: mciqtz32.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[ 2268:07b0] :LAUNCHER:WRAPPER: mciqtz32.dll -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 2268:07b0] :LAUNCHER:WRAPPER: mciqtz32.dll -> ole32.dll!0x774d057e = CoCreate
Instance
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c832b6e = GetPriv
ateProfileStringA
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c810b07 = GetFile
Size
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c809420 = CreateF
ileMappingW
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80b995 = MapView
OfFile
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVi
ewOfFile
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c810cfd = GetFile
InformationByHandle
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c8107f0 = CreateF
ileW
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c810c1e = SetFile
Pointer
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c801812 = ReadFil
e
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80b731 = GetModu
leHandleA
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80aedb = LoadLib
raryW
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80e4cd = GetModu
leHandleW
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c801d7b = LoadLib
raryA
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> KERNEL32.dll!0x7c80b55f = GetModu
leFileNameA
[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> ole32.dll!0x774d057e = CoCreateIn
stance

[ 2268:07b0] :LAUNCHER:WRAPPER: QUARTZ.dll -> OLEAUT32.dll!0x770f9d5a = LoadReg


TypeLib
[ 2268:07b0] :WRAPPER:LoadLibrary: mciqtz32.dll, handle is 621f0000
[ 2269:07b0] :WRAPPER: Search MCIAVI.mci in NULL
[ 2269:07b0] :WRAPPER: Search MPEGVide.mci in NULL
[ 2269:07b0] :WRAPPER:CoCreateInstance: {e436ebb3-524f-11ce-9f53-0020af0ba770}
[ 2269:07b0] :WRAPPER:CoCreateInstance/RIID: {56a8689f-0ad4-11ce-b03a-0020af0ba
770}
[ 2269:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2269:07b0] :WRAPPER:LoadLibrary: CLBCATQ.DLL
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c801af5 = LoadLi
braryExW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c801a28 = Create
FileA
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80e4cd = GetMod
uleHandleW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c8115cc = GetFil
eAttributesA
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c8094ee = Create
FileMappingA
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c801812 = ReadFi
le
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80ef71 = FindFi
rstFileW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80efca = FindNe
xtFileW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80ee67 = FindCl
ose
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80b7dc = GetFil
eAttributesW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80e76c = Search
PathW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c809420 = Create
FileMappingW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> ole32.dll!0x774d0526 = CoCreateI
nstanceEx
[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> ole32.dll!0x774d057e = CoCreateI
nstance

[ 2270:07b0] :LAUNCHER:WRAPPER: CLBCATQ.DLL -> OLEAUT32.dll!0x770f9d5a = LoadRe


gTypeLib
[ 2270:07b0] :WRAPPER:LoadLibrary: CLBCATQ.DLL, handle is 76f90000
[ 2270:07b0] :WRAPPER:LoadLibrary: CLBCATQ.DLL, handle is 76f90000
[ 2272:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\quartz.dll, handle is 74
7a0000
[ 2272:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\QUARTZ.dll
[ 2272:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\QUARTZ.dll, handle is 74
7a0000
[ 2273:0b60] :WRAPPER:CoCreateInstance: {cda42200-bd88-11d0-bd4e-00a0c911ce86}
[ 2273:0b60] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000
046}
[ 2273:0b60] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2274:0b60] :WRAPPER:CoCreateInstance: {e436ebb5-524f-11ce-9f53-0020af0ba770}
[ 2274:0b60] :WRAPPER:CoCreateInstance/RIID: {56a86895-0ad4-11ce-b03a-0020af0ba
770}
[ 2274:0b60] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2307:07b0] :WRAPPER:CoCreateInstance: {4315d437-5b8c-11d0-bd3b-00a0c911ce86}
[ 2307:07b0] :WRAPPER:CoCreateInstance/RIID: {0000011a-0000-0000-c000-000000000
046}
[ 2307:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\devenum.dll
[ 2308:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\devenum.dll
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c80e4cd = GetModuleHandleW
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c80ae30 = GetProcAddress
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c80aedb = LoadLibraryW
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c8449fd = SetUnhandledExceptionFilter
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c801af5 = LoadLibraryExW
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> KERNEL32.dll
!0x7c809bd7 = CloseHandle
[ 2308:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\devenum.dll -> ole32.dll!0x
774d057e = CoCreateInstance
[ 2308:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\devenum.dll, handle is 7
6600000
[ 2309:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\devenum.dll, handle is 7
6600000
[ 2309:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\devenum.dll
[ 2309:07b0] :WRAPPER:CoCreateInstanceEx: {00000000-0000-0000-0000-000000000000
}
[ 2309:07b0] :WRAPPER:(80070057)CoCreateInstanceEx
[ 2310:07b0] :WRAPPER:LoadLibrary: oleaut32.dll, handle is 770f0000
[ 2310:0b60] :WRAPPER:CoCreateInstanceEx: {00000000-0000-0000-0000-000000000000
}
[ 2310:0b60] :WRAPPER:(80070057)CoCreateInstanceEx
[ 2310:0b60] :WRAPPER:CoCreateInstance: {336475d0-942a-11ce-a870-00aa002feab5}
[ 2310:0b60] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000
046}
[ 2310:0b60] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2343:07b0] :WRAPPER:CoCreateInstance: {4315d437-5b8c-11d0-bd3b-00a0c911ce86}
[ 2343:07b0] :WRAPPER:CoCreateInstance/RIID: {0000011a-0000-0000-c000-000000000
046}
[ 2343:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\devenum.dll
[ 2343:0b60] :WRAPPER:CoCreateInstance: {4a2286e0-7bef-11ce-9bd9-0000e202599c}
[ 2343:0b60] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000

046}
[ 2344:0b60] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2344:07b0] :WRAPPER:CoCreateInstance: {4315d437-5b8c-11d0-bd3b-00a0c911ce86}
[ 2344:07b0] :WRAPPER:CoCreateInstance/RIID: {0000011a-0000-0000-c000-000000000
046}
[ 2344:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\devenum.dll
[ 2344:0b60] :WRAPPER:CoCreateInstance: {38be3000-dbf4-11d0-860e-00a024cfef6d}
[ 2344:0b60] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000
046}
[ 2345:0b60] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\l3codecx.ax
[ 2345:0b60] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\l3codecx.ax
[ 2346:0b60] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\l3codecx.ax -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 2346:0b60] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\l3codecx.ax -> KERNEL32.dll
!0x7c80b55f = GetModuleFileNameA
[ 2346:0b60] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\l3codecx.ax -> ole32.dll!0x
774d057e = CoCreateInstance
[ 2346:0b60] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\l3codecx.ax, handle is 7
2c50000
[ 2346:0b60] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\l3codecx.ax, handle is 7
2c50000
[ 2346:0b60] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\l3codecx.ax
[ 2347:07b0] :WRAPPER:CoCreateInstance: {4315d437-5b8c-11d0-bd3b-00a0c911ce86}
[ 2347:07b0] :WRAPPER:CoCreateInstance/RIID: {0000011a-0000-0000-c000-000000000
046}
[ 2347:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\devenum.dll
[ 2347:0b60] :WRAPPER:CoCreateInstance: {79376820-07d0-11cf-a24d-0020afd79767}
[ 2347:0b60] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000
046}
[ 2347:0b60] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2348:07b0] :WRAPPER:LoadLibrary: DSOUND.DLL
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c809bd7 = CloseHa
ndle
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c80e4cd = GetModu
leHandleW
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c810b07 = GetFile
Size
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c810c1e = SetFile
Pointer
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c801812 = ReadFil
e
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c8107f0 = CreateF
ileW
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c80ac6e = FreeLib
rary
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c80ae30 = GetProc
Address
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c80aedb = LoadLib
raryW
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c80ba04 = UnmapVi
ewOfFile
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c80b995 = MapView
OfFile
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c809420 = CreateF
ileMappingW
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> KERNEL32.dll!0x7c8449fd = SetUnha
ndledExceptionFilter
[ 2348:07b0] :LAUNCHER:WRAPPER: DSOUND.DLL -> ole32.dll!0x774d057e = CoCreateIn
stance
[ 2349:07b0] :WRAPPER:LoadLibrary: DSOUND.DLL, handle is 73e90000

[ 2349:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5


7043f)
[ 2349:07b0] :BOX: ReadFile 0x0090dcb4 <- 0x40 bytes at 0x0 'TRAINER V4.EXE'
[ 2354:07b0] :BOX: ReadFile(OK) 0x40 wasread 0x40 offs 0x0 'TRAINER V4.EXE'
[ 2354:07b0] :BOX: SetFilePointer(OK): SET 248(0xf8)/0x57043f, 0x40->0xf8 'TRAI
NER V4.EXE'
[ 2354:07b0] :BOX: ReadFile 0x0090dbac <- 0xf8 bytes at 0xf8 'TRAINER V4.EXE'
[ 2354:07b0] :BOX: ReadFile(OK) 0xf8 wasread 0xf8 offs 0xf8 'TRAINER V4.EXE'
[ 2354:07b0] :BOX: GetFileSize: 'TRAINER V4.EXE'
[ 2354:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 2354:07b0] :WRAPPER:LoadLibrary: setupapi.dll, handle is 778f0000
[ 2355:07b0] :WRAPPER:FreeLibrary:778f0000, 'C:\WINDOWS\system32\SETUPAPI.dll'
[ 2355:07b0] :WRAPPER:LoadLibrary: setupapi.dll, handle is 778f0000
[ 2360:07b0] :WRAPPER:FreeLibrary:778f0000, 'C:\WINDOWS\system32\SETUPAPI.dll'
[ 2361:07b0] :WRAPPER:LoadLibrary: setupapi.dll, handle is 778f0000
[ 2365:07b0] :WRAPPER:FreeLibrary:778f0000, 'C:\WINDOWS\system32\SETUPAPI.dll'
[ 2366:07b0] :WRAPPER:LoadLibrary: setupapi.dll, handle is 778f0000
[ 2366:07b0] :WRAPPER:FreeLibrary:778f0000, 'C:\WINDOWS\system32\SETUPAPI.dll'
[ 2368:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys
[ 2368:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys, ha
ndle is 03590001
[ 2368:07b0] :WRAPPER:FreeLibrary:03590001, '???'
[ 2368:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys
[ 2369:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys, ha
ndle is 03590001
[ 2369:07b0] :WRAPPER:FreeLibrary:03590001, '???'
[ 2369:07b0] :WRAPPER:LoadLibrary: KsUser.dll
[ 2369:07b0] :WRAPPER:LoadLibrary: KsUser.dll, handle is 73e60000
[ 2375:07b0] :WRAPPER:LoadLibrary: DSOUND.DLL, handle is 73e90000
[ 2375:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\DSOUND.DLL
[ 2375:07b0] :WRAPPER:FreeLibrary:73e90000, 'C:\WINDOWS\system32\DSOUND.DLL'
[ 2376:07b0] :WRAPPER:CoCreateInstance: {1e651cc0-b199-11d0-8212-00c04fc32c45}
[ 2376:07b0] :WRAPPER:CoCreateInstance/RIID: {56a8689c-0ad4-11ce-b03a-0020af0ba
770}
[ 2376:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2377:07b0] :WRAPPER:CoCreateInstance: {060af76c-68dd-11d0-8fc1-00c04fd9189d}
[ 2377:07b0] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000
046}
[ 2377:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\quartz.dll
[ 2378:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5
7043f)
[ 2378:07b0] :BOX: ReadFile 0x0090ee10 <- 0x40 bytes at 0x0 'TRAINER V4.EXE'
[ 2378:07b0] :BOX: ReadFile(OK) 0x40 wasread 0x40 offs 0x0 'TRAINER V4.EXE'
[ 2378:07b0] :BOX: SetFilePointer(OK): SET 248(0xf8)/0x57043f, 0x40->0xf8 'TRAI
NER V4.EXE'
[ 2378:07b0] :BOX: ReadFile 0x0090ed08 <- 0xf8 bytes at 0xf8 'TRAINER V4.EXE'
[ 2378:07b0] :BOX: ReadFile(OK) 0xf8 wasread 0xf8 offs 0xf8 'TRAINER V4.EXE'
[ 2378:07b0] :BOX: GetFileSize: 'TRAINER V4.EXE'
[ 2378:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 2379:07b0] :WRAPPER:LoadLibrary: setupapi.dll, handle is 778f0000
[ 2379:07b0] :WRAPPER:FreeLibrary:778f0000, 'C:\WINDOWS\system32\SETUPAPI.dll'
[ 2381:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys
[ 2381:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys, ha
ndle is 03e90001
[ 2381:07b0] :WRAPPER:FreeLibrary:03e90001, '???'
[ 2381:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys
[ 2382:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\Drivers\RtkHDAud.sys, ha
ndle is 03e90001
[ 2382:07b0] :WRAPPER:FreeLibrary:03e90001, '???'
[ 2385:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000

[ 2385:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'


[ 2385:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 2386:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 2386:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 2386:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 2386:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 2388:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 3786:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\asycfilt.dll
[ 3787:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\asycfilt.dll -> KERNEL32.dl
l!0x7c8449fd = SetUnhandledExceptionFilter
[ 3787:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\asycfilt.dll, handle is
70e20000
[ 4726:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 4726:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 4726:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 4726:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 4726:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 4726:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 4727:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 4728:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 8275:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 8275:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 8275:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 8276:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 8276:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 8276:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 8276:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 8278:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 8618:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 8618:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 8618:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 8618:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 8618:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 8618:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 8619:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 8620:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 8913:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 8913:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 8913:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 8913:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 8913:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 8913:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 8914:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 8915:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 9185:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000

[ 9185:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'


[ 9185:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 9186:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 9186:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 9186:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 9186:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 9188:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 9581:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 9581:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 9581:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 9581:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 9581:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 9581:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 9581:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 9591:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 9787:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 9787:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 9787:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 9787:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 9787:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 9787:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 9788:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 9789:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 10226:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 10226:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 10226:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 10226:07b0] :WRAPPER:LoadLibrary: shlwapi.dll, handle is 77f40000
[ 10226:07b0] :WRAPPER:FreeLibrary:77f40000, 'C:\WINDOWS\system32\SHLWAPI.dll'
[ 10226:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\All Users\Datos
de programa\Microsoft\Network\Connections\Pbk\rasphone.pbk
[ 10226:07b0] :WRAPPER:FindFirstFileW C:\WINDOWS\system32\Ras\*.pbk
[ 10228:07b0] :WRAPPER:FindFirstFileW C:\Documents and Settings\CABINA9\Datos de
programa\Microsoft\Network\Connections\Pbk\*.pbk
[ 10588:07b0] :WRAPPER:LoadLibrary: GDIPlus.dll
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c801a28 = Create
FileA
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c81cafa = ExitPr
ocess
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80e76c = Search
PathW
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c8217d2 = Search
PathA
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW

[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c809420 = Create


FileMappingW
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c801812 = ReadFi
le
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c8322d4 = Unlock
File
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c810cfd = GetFil
eInformationByHandle
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c832379 = LockFi
le
[ 10588:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c8094ee = Create
FileMappingA
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
uleHandleW
[ 10589:07b0] :LAUNCHER:WRAPPER: GDIPlus.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 10589:07b0] :WRAPPER:LoadLibrary: GDIPlus.dll, handle is 4eba0000
[ 10593:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 10593:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 10593:07b0] :WRAPPER:LoadLibrary: gdi32.dll, handle is 77ef0000
[ 10593:07b0] :WRAPPER:FreeLibrary:77ef0000, 'C:\WINDOWS\system32\GDI32.dll'
[ 10612:07b0] :WRAPPER:LoadLibrary: gdi32.dll, handle is 77ef0000
[ 10613:07b0] :WRAPPER:FreeLibrary:77ef0000, 'C:\WINDOWS\system32\GDI32.dll'
[ 10614:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 10615:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 10615:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 10615:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 10615:07b0] :WRAPPER:LoadLibrary: gdi32.dll, handle is 77ef0000
[ 10615:07b0] :WRAPPER:FreeLibrary:77ef0000, 'C:\WINDOWS\system32\GDI32.dll'
[ 10616:07b0] :WRAPPER:LoadLibrary: gdi32.dll, handle is 77ef0000
[ 10616:07b0] :WRAPPER:FreeLibrary:77ef0000, 'C:\WINDOWS\system32\GDI32.dll'
[ 10616:07b0] :WRAPPER:LoadLibrary: gdi32.dll, handle is 77ef0000
[ 10616:07b0] :WRAPPER:FreeLibrary:77ef0000, 'C:\WINDOWS\system32\GDI32.dll'
[ 10626:07b0] :WRAPPER: Search C:\DOCUME~1\CABINA9\CONFIG~1\Temp\124\34.bmp in N
ULL
[ 10627:07b0] :WRAPPER: Search C:\DOCUME~1\CABINA9\CONFIG~1\Temp\124\35.bmp in N
ULL
[ 10628:07b0] :WRAPPER: Search C:\DOCUME~1\CABINA9\CONFIG~1\Temp\124\36.bmp in N
ULL
[ 10629:07b0] :WRAPPER: Search C:\DOCUME~1\CABINA9\CONFIG~1\Temp\124\39.bmp in N
ULL
[ 10631:07b0] :WRAPPER: Search C:\DOCUME~1\CABINA9\CONFIG~1\Temp\124\31.bmp in N
ULL
[ 10632:07b0] :WRAPPER: Search C:\DOCUME~1\CABINA9\CONFIG~1\Temp\124\33.bmp in N

ULL
[ 13719:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\rundll32.exe
[ 13719:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\rundll32.exe, handle is
055d0001
[ 13719:07b0] :WRAPPER:FreeLibrary:055d0001, '???'
[ 13719:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\rundll32.exe
[ 13720:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\rundll32.exe, handle is
055d0001
[ 13720:07b0] :WRAPPER:FreeLibrary:055d0001, '???'
[ 13722:07b0] :WRAPPER:CoCreateInstance: {8856f961-340a-11d0-a96b-00c04fd705a2}
[ 13722:07b0] :WRAPPER:CoCreateInstance/RIID: {00000000-0000-0000-c000-000000000
046}
[ 13722:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\shdocvw.dll
[ 13723:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\shdocvw.dll
[ 13732:07b0] :WRAPPER:LoadLibrary: comctl32.dll, handle is 773a0000
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80b995 = MapVie
wOfFile
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c801d53 = LoadLi
braryExA
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80aedb = LoadLi
braryW
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c8094ee = Create
FileMappingA
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c809bd7 = CloseH
andle
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80e4cd = GetMod
uleHandleW
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c810c1e = SetFil
ePointer
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c801a28 = Create
FileA
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c810b07 = GetFil
eSize
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c80ba04 = UnmapV
iewOfFile
[ 13732:07b0] :LAUNCHER:WRAPPER: CRYPTUI.dll -> KERNEL32.dll!0x7c8107f0 = Create
FileW
[ 13732:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
!0x7c810c1e = SetFilePointer
[ 13733:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
!0x7c801812 = ReadFile
[ 13733:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
!0x7c810b07 = GetFileSize
[ 13733:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
!0x7c80ee67 = FindClose
[ 13733:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
!0x7c801a28 = CreateFileA
[ 13733:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
!0x7c81cafa = ExitProcess
[ 13733:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll

!0x7c8449fd =
[ 13733:07b0]
!0x7c80aedb =
[ 13733:07b0]
!0x7c80e4cd =
[ 13733:07b0]
!0x7c801d7b =
[ 13733:07b0]
!0x7c80ac6e =
[ 13733:07b0]
!0x7c80b731 =
[ 13733:07b0]
!0x7c80ae30 =
[ 13733:07b0]
!0x7c801d53 =
[ 13733:07b0]
!0x7c809bd7 =
[ 13733:07b0]
e210000
[ 13735:07b0]
e210000
[ 13735:07b0]
[ 13735:07b0]
[ 13736:07b0]
[ 13736:07b0]
[ 13736:07b0]
[ 13736:07b0]
[ 13737:07b0]
[ 13752:07b0]
[ 13752:07b0]
yW
[ 13752:07b0]
W
[ 13752:07b0]
ress
[ 13752:07b0]
y
[ 13752:07b0]
yA
[ 13752:07b0]
andleW
[ 13752:07b0]
[ 13752:07b0]
ileW
[ 13752:07b0]
leW
[ 13752:07b0]
ributesW
[ 13752:07b0]
e
[ 13752:07b0]
e
[ 13752:07b0]
fFile
[ 13752:07b0]
W
[ 13752:07b0]
MappingW
[ 13752:07b0]
ile

SetUnhandledExceptionFilter
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
LoadLibraryW
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
GetModuleHandleW
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
LoadLibraryA
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
FreeLibrary
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
GetModuleHandleA
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
GetProcAddress
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
LoadLibraryExA
:LAUNCHER:WRAPPER: C:\WINDOWS\system32\shdocvw.dll -> KERNEL32.dll
CloseHandle
:WRAPPER:LoadLibrary: C:\WINDOWS\system32\shdocvw.dll, handle is 7
:WRAPPER:LoadLibrary: C:\WINDOWS\system32\shdocvw.dll, handle is 7
:DLL_LOADER: fixuping imports of C:\WINDOWS\system32\shdocvw.dll
:WRAPPER:LoadLibrary: SHELL32.dll, handle is 7e6a0000
:WRAPPER:LoadLibrary: OLEAUT32.dll, handle is 770f0000
:WRAPPER:LoadLibrary: ole32.dll, handle is 774b0000
:WRAPPER:LoadLibrary: SHELL32.DLL, handle is 7e6a0000
:WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
:WRAPPER:LoadLibrary: WININET.dll, handle is 77180000
:WRAPPER:LoadLibrary: SXS.DLL
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80aedb = LoadLibrar
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80e76c = SearchPath
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80ae30 = GetProcAdd
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80ac6e = FreeLibrar
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c801d7b = LoadLibrar
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80e4cd = GetModuleH
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80ee67 = FindClose
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80ef71 = FindFirstF
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80efca = FindNextFi
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80b7dc = GetFileAtt
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c810b07 = GetFileSiz
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c809bd7 = CloseHandl
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80ba04 = UnmapViewO
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c8107f0 = CreateFile
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c809420 = CreateFile
:LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80b995 = MapViewOfF

[ 13752:07b0] :LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c801812 = ReadFile


[ 13752:07b0] :LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80b731 = GetModuleH
andleA
[ 13752:07b0] :LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c801af5 = LoadLibrar
yExW
[ 13752:07b0] :LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c80b55f = GetModuleF
ileNameA
[ 13752:07b0] :LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c810c1e = SetFilePoi
nter
[ 13752:07b0] :LAUNCHER:WRAPPER: SXS.DLL -> KERNEL32.dll!0x7c810cfd = GetFileInf
ormationByHandle
[ 13753:07b0] :WRAPPER:LoadLibrary: SXS.DLL, handle is 76980000
[ 13755:07b0] :WRAPPER:LoadLibrary: urlmon.dll, handle is 7df20000
[ 13756:07b0] :WRAPPER:LoadLibrary: urlmon.dll, handle is 7df20000
[ 13757:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\shdoclc.dll
[ 13757:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\shdoclc.dll, handle is 7
1800000
[ 13758:07b0] :WRAPPER:LoadLibrary: COMCTL32.dll, handle is 773a0000
[ 13759:07b0] :WRAPPER:LoadLibrary: xpsp2res.dll
[ 13759:07b0] :WRAPPER:LoadLibrary: xpsp2res.dll, handle is 05840000
[ 13760:07b0] :WRAPPER:LoadLibrary: URLMON.DLL, handle is 7df20000
[ 13760:07b0] :WRAPPER:FreeLibrary:7df20000, 'C:\WINDOWS\system32\urlmon.dll'
[ 13761:07b0] :WRAPPER:LoadLibrary: OLEAUT32.dll, handle is 770f0000
[ 13761:07b0] :WRAPPER:LoadLibrary: mlang.dll
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> GDI32.dll!0x77f0a005 = AddFontReso
urceA
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVie
wOfFile
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80b995 = MapViewO
fFile
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c8094ee = CreateFi
leMappingA
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c810b07 = GetFileS
ize
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c801a28 = CreateFi
leA
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80aedb = LoadLibr
aryW
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80e4cd = GetModul
eHandleW
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c809bd7 = CloseHan
dle
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80ae30 = GetProcA
ddress
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80b731 = GetModul
eHandleA
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c801d7b = LoadLibr
aryA
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibr
ary
[ 13765:07b0] :LAUNCHER:WRAPPER: mlang.dll -> KERNEL32.dll!0x7c80b55f = GetModul
eFileNameA
[ 13765:07b0] :WRAPPER:LoadLibrary: mlang.dll, handle is 75dd0000
[ 13766:08d0] :WRAPPER:LoadLibrary: WS2_32.dll, handle is 71a30000
[ 13766:07b0] :WRAPPER:LoadLibrary: MLANG.dll, handle is 75dd0000
[ 14047:06f0] :WRAPPER:LoadLibrary: C:\WINDOWS\System32\mswsock.dll, handle is 7
19d0000
[ 14642:07b0] :WRAPPER:CoGetClassObject: {8f6b0360-b80d-11d0-a9b3-006097942311}

[ 14642:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000


046}
[ 14642:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\urlmon.dll
[ 14643:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\urlmon.dll, handle is 7d
f20000
[ 14643:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\urlmon.dll
[ 14656:07b0] :WRAPPER:CoGetClassObject: {25336920-03f9-11cf-8fd0-00aa00686f13}
[ 14657:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 14657:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mshtml.dll
[ 14657:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mshtml.dll
[ 14658:07b0] :WRAPPER:LoadLibrary: VERSION.dll, handle is 77bd0000
[ 14658:07b0] :WRAPPER:LoadLibrary: C:\Archivos de programa\Microsoft Office\Off
ice12\outllib.dll
[ 14658:07b0] :WRAPPER:LoadLibrary: C:\Archivos de programa\Microsoft Office\Off
ice12\outllib.dll, error 126
[ 14659:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 14659:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c801d7b = LoadLibraryA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80ae30 = GetProcAddress
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80b731 = GetModuleHandleA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c809bd7 = CloseHandle
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80ba04 = UnmapViewOfFile
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80b995 = MapViewOfFile
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c8449fd = SetUnhandledExceptionFilter
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c832b6e = GetPrivateProfileStringA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c801d53 = LoadLibraryExA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80ac6e = FreeLibrary
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80b55f = GetModuleFileNameA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c810c1e = SetFilePointer
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c801812 = ReadFile
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c810b07 = GetFileSize
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80ee67 = FindClose
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c80e4cd = GetModuleHandleW
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c8217d2 = SearchPathA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c8353e6 = _lread
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c8094ee = CreateFileMappingA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> KERNEL32.dll!
0x7c801a28 = CreateFileA
[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> ole32.dll!0x7
74e56c5 = CoGetClassObject

[ 14659:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtml.dll -> ole32.dll!0x7


74d057e = CoCreateInstance
[ 14660:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mshtml.dll, handle is 7d
be0000
[ 14661:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mshtml.dll, handle is 7d
be0000
[ 14661:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\mshtml.dll
[ 14665:07b0] :WRAPPER:LoadLibrary: comctl32.dll, handle is 773a0000
[ 14665:07b0] :WRAPPER:LoadLibrary: urlmon.dll, handle is 7df20000
[ 14665:07b0] :WRAPPER:CoGetClassObject: {3050f406-98b5-11cf-bb82-00aa00bdce0b}
[ 14665:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 14665:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mshtml.dll
[ 14666:07b0] :WRAPPER:CoGetClassObject: {3050f406-98b5-11cf-bb82-00aa00bdce0b}
[ 14666:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 14666:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mshtml.dll
[ 14666:07b0] :WRAPPER:CoGetClassObject: {3050f406-98b5-11cf-bb82-00aa00bdce0b}
[ 14666:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 14666:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mshtml.dll
[ 14667:07b0] :WRAPPER:LoadLibrary: OLEAUT32.dll, handle is 770f0000
[ 14668:07b0] :WRAPPER:LoadLibrary: URLMON.DLL, handle is 7df20000
[ 14668:07b0] :WRAPPER:FreeLibrary:7df20000, 'C:\WINDOWS\system32\urlmon.dll'
[ 14669:07b0] :WRAPPER:CoGetClassObject: {7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}
[ 14669:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 14669:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\urlmon.dll
[ 14670:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\urlmon.dll, handle is 7d
f20000
[ 14674:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\shdoclc.dll, handle is 7
1800000
[ 15693:07b0] :WRAPPER:CoCreateInstance: {50d5107a-d278-4871-8989-f4ceaaf59cfc}
[ 15693:07b0] :WRAPPER:CoCreateInstance/RIID: {08c0e040-62d1-11d1-9326-0060b067b
86e}
[ 15693:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\msimtf.dll
[ 15693:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msimtf.dll
[ 15693:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msimtf.dll -> KERNEL32.dll!
0x7c80ac6e = FreeLibrary
[ 15693:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msimtf.dll -> KERNEL32.dll!
0x7c8449fd = SetUnhandledExceptionFilter
[ 15693:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msimtf.dll -> KERNEL32.dll!
0x7c80ae30 = GetProcAddress
[ 15693:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msimtf.dll -> KERNEL32.dll!
0x7c80b55f = GetModuleFileNameA
[ 15693:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msimtf.dll -> KERNEL32.dll!
0x7c801d7b = LoadLibraryA
[ 15693:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msimtf.dll -> KERNEL32.dll!
0x7c80b731 = GetModuleHandleA
[ 15694:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msimtf.dll, handle is 74
680000
[ 15695:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msimtf.dll, handle is 74
680000
[ 15695:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\msimtf.dll
[ 15696:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\ole32.dll, handle is 774
b0000
[ 15696:07b0] :WRAPPER:CoCreateInstance: {3ce74de4-53d3-4d74-8b83-431b3828ba53}
[ 15696:07b0] :WRAPPER:CoCreateInstance/RIID: {8ded7393-5db1-475c-9e71-a39111b0f
f67}
[ 15696:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\msctf.dll

[ 15697:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msctf.dll, handle is 746


b0000
[ 15697:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\MSCTF.dll
[ 15697:07b0] :WRAPPER:CoCreateInstance: {a4b544a1-438d-4b41-9325-869523e2d6c7}
[ 15697:07b0] :WRAPPER:CoCreateInstance/RIID: {c3acefb5-f69d-4905-938f-fcadcf4be
830}
[ 15697:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\msctf.dll
[ 15698:07b0] :WRAPPER:LoadLibrary: OLEAUT32.DLL, handle is 770f0000
[ 15699:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\ole32.dll, handle is 774
b0000
[ 15699:07b0] :WRAPPER:CoCreateInstance: {fa445657-9379-11d6-b41a-00065b83ee53}
[ 15699:07b0] :WRAPPER:CoCreateInstance/RIID: {aa80e7f7-2021-11d2-93e0-0060b067b
86e}
[ 15699:07b0] :WRAPPER:LoadLibrary: OLEAUT32.DLL, handle is 770f0000
[ 15700:07b0] :WRAPPER:CoCreateInstance: {f414c260-6ac0-11cf-b6d1-00aa00bbbb58}
[ 15700:07b0] :WRAPPER:CoCreateInstance/RIID: {bb1a2ae1-a4f9-11cf-8f20-00805f2cd
064}
[ 15700:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\jscript.dll
[ 15700:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\jscript.dll
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> OLEAUT32.dll
!0x770f9d5a = LoadRegTypeLib
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> ole32.dll!0x
774e56c5 = CoGetClassObject
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> ole32.dll!0x
774d057e = CoCreateInstance
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c801af5 = LoadLibraryExW
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80b995 = MapViewOfFile
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c8449fd = SetUnhandledExceptionFilter
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80e4cd = GetModuleHandleW
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c809bd7 = CloseHandle
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c801d7b = LoadLibraryA
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80ae30 = GetProcAddress
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c801d53 = LoadLibraryExA
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80b731 = GetModuleHandleA
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80b55f = GetModuleFileNameA
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c809420 = CreateFileMappingW
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c8107f0 = CreateFileW
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80ba04 = UnmapViewOfFile
[ 15701:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\jscript.dll -> KERNEL32.dll
!0x7c80e76c = SearchPathW
[ 15701:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\jscript.dll, handle is 7
5c00000
[ 15702:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\jscript.dll, handle is 7
5c00000
[ 15702:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\jscript.dll

[ 15702:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000


[ 15702:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15702:07b0] :WRAPPER:CoCreateInstance: {00000323-0000-0000-c000-000000000046}
[ 15702:07b0] :WRAPPER:CoCreateInstance/RIID: {00000146-0000-0000-c000-000000000
046}
[ 15702:07b0] :WRAPPER:CoCreateInstance: {6c736db1-bd94-11d0-8a23-00aa00b58e10}
[ 15702:07b0] :WRAPPER:CoCreateInstance/RIID: {6c736dc1-ab0d-11d0-a2ad-00a0c90f2
7e8}
[ 15703:07b0] :WRAPPER:LoadLibrary: xpsp2res.dll, handle is 05840000
[ 15704:07b0] :WRAPPER:LoadLibrary: OLE32, handle is 774b0000
[ 15705:0278] :WRAPPER:LoadLibrary: OLE32.DLL, handle is 774b0000
[ 15707:07b0] :WRAPPER:LoadLibrary: mshtml.dll, handle is 7dbe0000
[ 15708:07b0] :WRAPPER:CoGetClassObject: {d27cdb6e-ae6d-11cf-96b8-444553540000}
[ 15708:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 15708:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\Macromed\Flash\Flash3
2_11_2_202_228.ocx
[ 15709:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\Macromed\Flash\Flash32_1
1_2_202_228.ocx
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> OLEAUT32.dll!0x770f9d5a = LoadRegTypeLib
[ 15711:07b0] :LAUNCHER:WRAPPER: MSIMG32.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c8115cc = GetFileAttributesA
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c801d7b = LoadLibraryA
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80b55f = GetModuleFileNameA
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c801af5 = LoadLibraryExW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80ee67 = FindClose
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80efca = FindNextFileW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80ef71 = FindFirstFileW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c8107f0 = CreateFileW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80b7dc = GetFileAttributesW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c801a28 = CreateFileA
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c810c1e = SetFilePointer
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c801812 = ReadFile
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c810b07 = GetFileSize
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c8449fd = SetUnhandledExceptionFilter
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c810cfd = GetFileInformationByHandle
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80ba04 = UnmapViewOfFile
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80b995 = MapViewOfFile
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c8094ee = CreateFileMappingA
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2

_202_228.ocx -> KERNEL32.dll!0x7c80b731 = GetModuleHandleA


[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c81cafa = ExitProcess
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80e4cd = GetModuleHandleW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80ac6e = FreeLibrary
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c809bd7 = CloseHandle
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80aedb = LoadLibraryW
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> KERNEL32.dll!0x7c80ae30 = GetProcAddress
[ 15711:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2
_202_228.ocx -> ole32.dll!0x774d057e = CoCreateInstance
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80aedb = LoadLibr
aryW
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c810c1e = SetFileP
ointer
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c809bd7 = CloseHan
dle
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80ba04 = UnmapVie
wOfFile
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80b995 = MapViewO
fFile
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c809420 = CreateFi
leMappingW
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c810b07 = GetFileS
ize
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c8107f0 = CreateFi
leW
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80b7dc = GetFileA
ttributesW
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibr
ary
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80ae30 = GetProcA
ddress
[ 15711:07b0] :LAUNCHER:WRAPPER: mscms.dll -> KERNEL32.dll!0x7c80e4cd = GetModul
eHandleW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80ac6e = FreeL
ibrary
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80aedb = LoadL
ibraryW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c809bd7 = Close
Handle
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c801af5 = LoadL
ibraryExW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80b7dc = GetFi
leAttributesW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c8107f0 = Creat
eFileW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c801d7b = LoadL
ibraryA
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80e4cd = GetMo
duleHandleW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80e76c = Searc

hPathW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80ee67 = FindC
lose
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80ef71 = FindF
irstFileW
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c810b07 = GetFi
leSize
[ 15711:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c801812 = ReadF
ile
[ 15712:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c810c1e = SetFi
lePointer
[ 15712:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[ 15712:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80b995 = MapVi
ewOfFile
[ 15712:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c80ba04 = Unmap
ViewOfFile
[ 15712:07b0] :LAUNCHER:WRAPPER: WINSPOOL.DRV -> KERNEL32.dll!0x7c809420 = Creat
eFileMappingW
[ 15712:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\Macromed\Flash\Flash32_1
1_2_202_228.ocx, handle is 10000000
[ 15713:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\Macromed\Flash\Flash32_1
1_2_202_228.ocx, handle is 10000000
[ 15713:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\Macromed\Flas
h\Flash32_11_2_202_228.ocx
[ 15713:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15714:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15714:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15714:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15714:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15714:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
sgn
[ 15714:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
cfg
[ 15715:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
sgn
[ 15715:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15715:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15715:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15715:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15715:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15716:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15716:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15716:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15716:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15716:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15716:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15716:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15718:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Adobe\Flash Player\AssetCache
[ 15718:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Adobe\Flash Player\AssetCache\*
[ 15718:07b0] :WRAPPER:LoadLibrary: ieframe.dll
[ 15719:07b0] :WRAPPER:LoadLibrary: ieframe.dll, error 126
[ 15719:07b0] :WRAPPER:CoCreateInstance: {0002e005-0000-0000-c000-000000000046}
[ 15719:07b0] :WRAPPER:CoCreateInstance/RIID: {0002e013-0000-0000-c000-000000000
046}
[ 15719:07b0] :WRAPPER: INPROC SERVER OLE32.DLL
[ 15724:07b0] :WRAPPER:LoadLibrary: oleaut32.dll, handle is 770f0000
[ 15725:07b0] :WRAPPER:LoadLibrary: WININET.dll, handle is 77180000

[ 15732:07b0] :WRAPPER:LoadLibrary: Kernel32.dll, handle is 7c800000


[ 15732:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15732:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15732:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15732:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15773:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15773:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15773:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15773:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15777:07b0] :WRAPPER:LoadLibrary: MLANG.dll, handle is 75dd0000
[ 15792:07b0] :WRAPPER:CoGetClassObject: {d27cdb6e-ae6d-11cf-96b8-444553540000}
[ 15792:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 15792:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\Macromed\Flash\Flash3
2_11_2_202_228.ocx
[ 15792:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15792:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15793:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15793:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15793:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
sgn
[ 15793:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
cfg
[ 15793:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
sgn
[ 15793:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15793:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15793:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15793:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15793:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15794:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15794:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15794:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15794:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15794:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15794:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15794:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15795:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Adobe\Flash Player\AssetCache
[ 15795:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Adobe\Flash Player\AssetCache\*
[ 15795:07b0] :WRAPPER:LoadLibrary: ieframe.dll
[ 15795:07b0] :WRAPPER:LoadLibrary: ieframe.dll, error 126
[ 15796:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15796:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15796:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15796:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15837:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15837:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15837:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15837:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15850:07b0] :WRAPPER:LoadLibrary: URLMON.DLL, handle is 7df20000
[ 15850:07b0] :WRAPPER:FreeLibrary:7df20000, 'C:\WINDOWS\system32\urlmon.dll'
[ 15851:07b0] :WRAPPER:LoadLibrary: xpsp2res.dll, handle is 05840000
[ 15864:07b0] :WRAPPER:Search: C:\WINDOWS\system32\Macromed\Flash\Flash32_11_2_2
02_228.ocx in NULL
[ 15864:07b0] :WRAPPER:CoGetClassObject: {d27cdb6e-ae6d-11cf-96b8-444553540000}
[ 15864:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 15864:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\Macromed\Flash\Flash3

2_11_2_202_228.ocx
[ 15864:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15865:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15865:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15865:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15865:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
sgn
[ 15865:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
cfg
[ 15865:07b0] :WRAPPER:FindFirstFileW \\?\C:\WINDOWS\system32\Macromed\Flash\ss.
sgn
[ 15866:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 15866:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 15866:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 15866:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 15866:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15866:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15866:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15866:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15866:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 15867:07b0] :WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
[ 15867:07b0] :WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
[ 15867:07b0] :WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
[ 15867:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Adobe\Flash Player\AssetCache
[ 15867:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Adobe\Flash Player\AssetCache\*
[ 15867:07b0] :WRAPPER:LoadLibrary: ieframe.dll
[ 15868:07b0] :WRAPPER:LoadLibrary: ieframe.dll, error 126
[ 15869:07b0] :WRAPPER:LoadLibrary: \\?\C:\Documents and Settings\CABINA9\Mis do
cumentos\Downloads\trainer v4\trainer v4.exe, handle is 00400000
[ 15869:07b0] :WRAPPER:FreeLibrary:00400000, 'C:\Documents and Settings\CABINA9\
Mis documentos\Downloads\trainer v4\trainer v4.exe'
[ 15869:07b0] :WRAPPER:LoadLibrary: \\?\C:\Documents and Settings\CABINA9\Mis do
cumentos\Downloads\trainer v4\trainer v4.exe, handle is 00400000
[ 15869:07b0] :WRAPPER:FreeLibrary:00400000, 'C:\Documents and Settings\CABINA9\
Mis documentos\Downloads\trainer v4\trainer v4.exe'
[ 15877:07b0] :WRAPPER:CoCreateInstance: {4fd2a832-86c8-11d0-8fca-00c04fd9189d}
[ 15877:07b0] :WRAPPER:CoCreateInstance/RIID: {4fd2a833-86c8-11d0-8fca-00c04fd91
89d}
[ 15877:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\ddrawex.dll
[ 15882:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\ddrawex.dll
[ 15886:07b0] :LAUNCHER:WRAPPER: DCIMAN32.dll -> KERNEL32.dll!0x7c8449fd = SetUn
handledExceptionFilter
[ 15886:07b0] :LAUNCHER:WRAPPER: DCIMAN32.dll -> KERNEL32.dll!0x7c80ae30 = GetPr
ocAddress
[ 15886:07b0] :LAUNCHER:WRAPPER: DCIMAN32.dll -> KERNEL32.dll!0x7c80b731 = GetMo
duleHandleA
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c801a28 = CreateFi
leA
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c801812 = ReadFile
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c810c1e = SetFileP
ointer
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c80b55f = GetModul
eFileNameA
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c8449fd = SetUnhan
dledExceptionFilter
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c809bd7 = CloseHan
dle
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c80ac6e = FreeLibr

ary
[ 15886:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c80ae30 = GetProcA
ddress
[ 15887:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c801d7b = LoadLibr
aryA
[ 15887:07b0] :LAUNCHER:WRAPPER: DDRAW.dll -> KERNEL32.dll!0x7c80b731 = GetModul
eHandleA
[ 15887:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\ddrawex.dll -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 15887:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\ddrawex.dll -> KERNEL32.dll
!0x7c801d7b = LoadLibraryA
[ 15887:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\ddrawex.dll -> KERNEL32.dll
!0x7c8449fd = SetUnhandledExceptionFilter
[ 15887:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\ddrawex.dll -> KERNEL32.dll
!0x7c80b55f = GetModuleFileNameA
[ 15887:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\ddrawex.dll -> KERNEL32.dll
!0x7c80ae30 = GetProcAddress
[ 15887:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\ddrawex.dll, handle is 6
d940000
[ 15888:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\ddrawex.dll, handle is 6
d940000
[ 15888:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\ddrawex.dll
[ 15888:07b0] :WRAPPER:LoadLibrary: ddraw.dll, handle is 736e0000
[ 15888:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\DDRAW.dll, handle is 736
e0000
[ 15888:07b0] :WRAPPER:FreeLibrary:736e0000, 'C:\WINDOWS\system32\DDRAW.dll'
[ 15889:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\DDRAW.dll, handle is 736
e0000
[ 15889:07b0] :WRAPPER:FreeLibrary:736e0000, 'C:\WINDOWS\system32\DDRAW.dll'
[ 15892:07b0] :BOX:OpenFile: found 'TRAINER V4.EXE' at 0x6df60, size 5702719(0x5
7043f)
[ 15892:07b0] :BOX: ReadFile 0x0090e0c4 <- 0x40 bytes at 0x0 'TRAINER V4.EXE'
[ 15892:07b0] :BOX: ReadFile(OK) 0x40 wasread 0x40 offs 0x0 'TRAINER V4.EXE'
[ 15892:07b0] :BOX: SetFilePointer(OK): SET 248(0xf8)/0x57043f, 0x40->0xf8 'TRAI
NER V4.EXE'
[ 15892:07b0] :BOX: ReadFile 0x0090dfa8 <- 0xf8 bytes at 0xf8 'TRAINER V4.EXE'
[ 15892:07b0] :BOX: ReadFile(OK) 0xf8 wasread 0xf8 offs 0xf8 'TRAINER V4.EXE'
[ 15892:07b0] :BOX:CloseFile: 'TRAINER V4.EXE'
[ 15898:07b0] :WRAPPER:LoadLibrary: Secur32.dll, handle is 77fc0000
[ 15898:07b0] :WRAPPER:LoadLibrary: crypt32.dll, handle is 77a50000
[ 15898:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\schannel.dll
[ 15899:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\schannel.dll -> KERNEL32.dl
l!0x7c80ac6e = FreeLibrary
[ 15899:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\schannel.dll -> KERNEL32.dl
l!0x7c80aedb = LoadLibraryW
[ 15899:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\schannel.dll -> KERNEL32.dl
l!0x7c80ae30 = GetProcAddress
[ 15899:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\schannel.dll -> KERNEL32.dl
l!0x7c809bd7 = CloseHandle
[ 15899:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\schannel.dll -> KERNEL32.dl
l!0x7c8449fd = SetUnhandledExceptionFilter
[ 15899:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\schannel.dll -> KERNEL32.dl
l!0x7c801d7b = LoadLibraryA
[ 15899:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\schannel.dll, handle is
767b0000
[ 15922:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Macromedia\Flash Player\#SharedObjects
[ 15922:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato
s de programa\Macromedia\Flash Player\#SharedObjects\*
[ 15922:07b0] :WRAPPER:FindFirstFileW \\?\C:\Documents and Settings\CABINA9\Dato

s de programa\Macromedia\Flash Player\#SharedObjects\453B56FV\macromedia.com\sup
port\flashplayer\sys\settings.sol
[ 16392:0898] :WRAPPER:LoadLibrary: ImgUtil.dll
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> KERNEL32.dll!0x7c8449fd = SetUnh
andledExceptionFilter
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> KERNEL32.dll!0x7c80b55f = GetMod
uleFileNameA
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> KERNEL32.dll!0x7c80b731 = GetMod
uleHandleA
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> KERNEL32.dll!0x7c80ae30 = GetPro
cAddress
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> KERNEL32.dll!0x7c801d7b = LoadLi
braryA
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> KERNEL32.dll!0x7c80ac6e = FreeLi
brary
[ 16400:0898] :LAUNCHER:WRAPPER: ImgUtil.dll -> ole32.dll!0x774d057e = CoCreateI
nstance
[ 16400:0898] :WRAPPER:LoadLibrary: ImgUtil.dll, handle is 66d30000
[ 16400:0898] :WRAPPER:CoCreateInstance: {30c3b080-30fb-11d0-b724-00aa006c1a01}
[ 16400:0898] :WRAPPER:CoCreateInstance/RIID: {d9e89500-30fa-11d0-b724-00aa006c1
a01}
[ 16400:0898] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
[ 16401:0898] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\imgutil.dll, handle is 6
6d30000
[ 16401:0898] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\ImgUtil.dll
[ 16401:0898] :WRAPPER:CoCreateInstance: {6a01fda0-30df-11d0-b724-00aa006c1a01}
[ 16401:0898] :WRAPPER:CoCreateInstance/RIID: {4ef17940-30e0-11d0-b724-00aa006c1
a01}
[ 16401:0898] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
[ 16409:0898] :WRAPPER:CoCreateInstance: {a3ccedf7-2de2-11d0-86f4-00a0c913f750}
[ 16409:0898] :WRAPPER:CoCreateInstance/RIID: {a3ccedf3-2de2-11d0-86f4-00a0c913f
750}
[ 16409:0898] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\pngfilt.dll
[ 16409:0898] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\pngfilt.dll
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> KERNEL32.dll
!0x7c8449fd = SetUnhandledExceptionFilter
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> KERNEL32.dll
!0x7c80b731 = GetModuleHandleA
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> KERNEL32.dll
!0x7c80ae30 = GetProcAddress
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> KERNEL32.dll
!0x7c801d7b = LoadLibraryA
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> KERNEL32.dll
!0x7c80b55f = GetModuleFileNameA
[ 16410:0898] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\pngfilt.dll -> ole32.dll!0x
774d057e = CoCreateInstance
[ 16410:0898] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\pngfilt.dll, handle is 5
e730000
[ 16411:0898] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\pngfilt.dll, handle is 5
e730000
[ 16411:0898] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\pngfilt.dll
[ 16982:07b0] :WRAPPER:CoCreateInstance: {f414c260-6ac0-11cf-b6d1-00aa00bbbb58}
[ 16982:07b0] :WRAPPER:CoCreateInstance/RIID: {bb1a2ae1-a4f9-11cf-8f20-00805f2cd
064}
[ 16982:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\jscript.dll
[ 16983:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 16983:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 16983:07b0] :WRAPPER:CoCreateInstance: {6c736db1-bd94-11d0-8a23-00aa00b58e10}

[ 16983:07b0]
7e8}
[ 16984:07b0]
[ 16984:07b0]
[ 17686:0898]
[ 17686:0898]
a01}
[ 17686:0898]
[ 17687:0898]
[ 17687:0898]
a01}
[ 17687:0898]
[ 17687:0898]
[ 17687:0898]
750}
[ 17687:0898]
[ 17803:07b0]
5c00000
[ 17803:07b0]
[ 17810:07b0]
[ 17811:092c]
[ 17811:092c]
[ 17812:092c]
[ 17812:092c]
[ 17812:092c]
[ 17812:092c]
[ 17812:092c]
[ 17812:092c]
[ 18245:0898]
[ 18245:0898]
a01}
[ 18245:0898]
[ 18245:0898]
[ 18245:0898]
a01}
[ 18245:0898]
[ 18245:0898]
[ 18245:0898]
750}
[ 18245:0898]
[ 18687:07b0]
[ 18687:07b0]
064}
[ 18687:07b0]
[ 18687:07b0]
[ 18687:07b0]
[ 18687:07b0]
[ 18687:07b0]
7e8}
[ 18706:07b0]
[ 18707:07b0]
[ 18820:0898]
[ 18821:0898]
a01}
[ 18821:0898]
[ 18821:0898]
[ 18821:0898]
a01}
[ 18821:0898]
[ 18821:0898]

:WRAPPER:CoCreateInstance/RIID: {6c736dc1-ab0d-11d0-a2ad-00a0c90f2
:WRAPPER:LoadLibrary: URLMON.DLL, handle is 7df20000
:WRAPPER:FreeLibrary:7df20000, 'C:\WINDOWS\system32\urlmon.dll'
:WRAPPER:CoCreateInstance: {30c3b080-30fb-11d0-b724-00aa006c1a01}
:WRAPPER:CoCreateInstance/RIID: {d9e89500-30fa-11d0-b724-00aa006c1
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
:WRAPPER:CoCreateInstance: {6a01fda0-30df-11d0-b724-00aa006c1a01}
:WRAPPER:CoCreateInstance/RIID: {4ef17940-30e0-11d0-b724-00aa006c1
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
:WRAPPER:CoCreateInstance: {a3ccedf7-2de2-11d0-86f4-00a0c913f750}
:WRAPPER:CoCreateInstance/RIID: {a3ccedf3-2de2-11d0-86f4-00a0c913f
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\pngfilt.dll
:WRAPPER:LoadLibrary: C:\WINDOWS\system32\jscript.dll, handle is 7
:WRAPPER: Search C:\WINDOWS\system32\jscript.dll in NULL
:WRAPPER:FreeLibrary:75c00000, 'C:\WINDOWS\system32\jscript.dll'
:WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
:WRAPPER:LoadLibrary: user32.dll, handle is 7e390000
:WRAPPER:LoadLibrary: shell32.dll, handle is 7e6a0000
:WRAPPER:LoadLibrary: version.dll, handle is 77bd0000
:WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
:WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
:WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
:WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
:WRAPPER:CoCreateInstance: {30c3b080-30fb-11d0-b724-00aa006c1a01}
:WRAPPER:CoCreateInstance/RIID: {d9e89500-30fa-11d0-b724-00aa006c1
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
:WRAPPER:CoCreateInstance: {6a01fda0-30df-11d0-b724-00aa006c1a01}
:WRAPPER:CoCreateInstance/RIID: {4ef17940-30e0-11d0-b724-00aa006c1
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
:WRAPPER:CoCreateInstance: {a3ccedf7-2de2-11d0-86f4-00a0c913f750}
:WRAPPER:CoCreateInstance/RIID: {a3ccedf3-2de2-11d0-86f4-00a0c913f
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\pngfilt.dll
:WRAPPER:CoCreateInstance: {f414c260-6ac0-11cf-b6d1-00aa00bbbb58}
:WRAPPER:CoCreateInstance/RIID: {bb1a2ae1-a4f9-11cf-8f20-00805f2cd
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\jscript.dll
:WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
:WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
:WRAPPER:CoCreateInstance: {6c736db1-bd94-11d0-8a23-00aa00b58e10}
:WRAPPER:CoCreateInstance/RIID: {6c736dc1-ab0d-11d0-a2ad-00a0c90f2
:WRAPPER:LoadLibrary: USER32.DLL, handle is 7e390000
:WRAPPER:LoadLibrary: UxTheme.dll, handle is 5b150000
:WRAPPER:CoCreateInstance: {30c3b080-30fb-11d0-b724-00aa006c1a01}
:WRAPPER:CoCreateInstance/RIID: {d9e89500-30fa-11d0-b724-00aa006c1
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
:WRAPPER:CoCreateInstance: {6a01fda0-30df-11d0-b724-00aa006c1a01}
:WRAPPER:CoCreateInstance/RIID: {4ef17940-30e0-11d0-b724-00aa006c1
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\imgutil.dll
:WRAPPER:CoCreateInstance: {a3ccedf7-2de2-11d0-86f4-00a0c913f750}

[ 18821:0898] :WRAPPER:CoCreateInstance/RIID: {a3ccedf3-2de2-11d0-86f4-00a0c913f


750}
[ 18821:0898] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\pngfilt.dll
[ 25740:07b0] :WRAPPER:LoadLibrary: COMCTL32.dll, handle is 773a0000
[ 26052:07b0] :WRAPPER:CoCreateInstance: {fa445657-9379-11d6-b41a-00065b83ee53}
[ 26052:07b0] :WRAPPER:CoCreateInstance/RIID: {aa80e7f7-2021-11d2-93e0-0060b067b
86e}
[ 26053:07b0] :WRAPPER:CoCreateInstance: {3050f4f5-98b5-11cf-bb82-00aa00bdce0b}
[ 26053:07b0] :WRAPPER:CoCreateInstance/RIID: {3050f7fa-98b5-11cf-bb82-00aa00bdc
e0b}
[ 26053:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mshtmled.dll
[ 26053:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mshtmled.dll
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c8449fd = SetUnhandledExceptionFilter
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c80ac6e = FreeLibrary
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c809bd7 = CloseHandle
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c810b07 = GetFileSize
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c80b55f = GetModuleFileNameA
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c80ae30 = GetProcAddress
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c80b731 = GetModuleHandleA
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c801d7b = LoadLibraryA
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> KERNEL32.dl
l!0x7c801812 = ReadFile
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> ole32.dll!0
x774d057e = CoCreateInstance
[ 26054:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\mshtmled.dll -> OLEAUT32.dl
l!0x770f9d5a = LoadRegTypeLib
[ 26054:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mshtmled.dll, handle is
75d50000
[ 26055:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mshtmled.dll, handle is
75d50000
[ 26055:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\mshtmled.dll
[ 26124:07b0] :WRAPPER:CoGetClassObject: {ed8c108e-4349-11d2-91a4-00c04f7969e8}
[ 26124:07b0] :WRAPPER:CoGetClassObject/RIID: {00000001-0000-0000-c000-000000000
046}
[ 26124:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\msxml3.dll
[ 26124:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msxml3.dll
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c8449fd = SetUnhandledExceptionFilter
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c809bd7 = CloseHandle
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c80ae30 = GetProcAddress
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c80e4cd = GetModuleHandleW
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c80ac6e = FreeLibrary
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c801af5 = LoadLibraryExW
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c80aedb = LoadLibraryW
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c801d7b = LoadLibraryA

[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!


0x7c810c1e = SetFilePointer
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c8107f0 = CreateFileW
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c801812 = ReadFile
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c81cafa = ExitProcess
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c80b731 = GetModuleHandleA
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> KERNEL32.dll!
0x7c80b55f = GetModuleFileNameA
[ 26125:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\msxml3.dll -> ole32.dll!0x7
74d057e = CoCreateInstance
[ 26125:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msxml3.dll, handle is 74
910000
[ 26126:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\msxml3.dll, handle is 74
910000
[ 26126:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\msxml3.dll
[ 26137:07b0] :WRAPPER:CoCreateInstance: {00000323-0000-0000-c000-000000000046}
[ 26137:07b0] :WRAPPER:CoCreateInstance/RIID: {00000146-0000-0000-c000-000000000
046}
[ 26137:07b0] :WRAPPER:LoadLibrary: OLEAUT32.dll, handle is 770f0000
[ 26148:07b0] :WRAPPER:LoadLibrary: urlmon.dll, handle is 7df20000
[ 26148:07b0] :WRAPPER:LoadLibrary: WININET.dll, handle is 77180000
[ 26148:07b0] :WRAPPER:CoCreateInstance: {7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}
[ 26148:07b0] :WRAPPER:CoCreateInstance/RIID: {79eac9ee-baf9-11ce-8c82-00aa004ba
90b}
[ 26149:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\urlmon.dll
[ 26150:07b0] :WRAPPER:LoadLibrary: USER32.dll, handle is 7e390000
[ 26158:07b0] :WRAPPER:CoCreateInstance: {275c23e2-3747-11d0-9fea-00aa003f8646}
[ 26158:07b0] :WRAPPER:CoCreateInstance/RIID: {275c23e1-3747-11d0-9fea-00aa003f8
646}
[ 26158:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mlang.dll
[ 26159:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\mlang.dll, handle is 75d
d0000
[ 26159:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\mlang.dll
[ 26159:07b0] :WRAPPER:LoadLibrary: OLEAUT32.DLL, handle is 770f0000
[ 26687:07b0] :WRAPPER:LoadLibrary: WINMM.dll, handle is 76b00000
[ 26687:07b0] :WRAPPER: Search C:\WINDOWS\media\Inicio de Windows XP.wav in NULL
[ 26687:07b0]
[ 26687:07b0]
[ 27769:07b0]
[ 27769:07b0]
e0b}
[ 27769:07b0]
[ 27777:07b0]
[ 27784:07b0]
andleW
[ 27784:07b0]
y
[ 27784:07b0]
ress
[ 27784:07b0]
yW
[ 27784:07b0]
yExW
[ 27784:07b0]
e

:WRAPPER:LoadLibrary: URLMON.DLL, handle is 7df20000


:WRAPPER:FreeLibrary:7df20000, 'C:\WINDOWS\system32\urlmon.dll'
:WRAPPER:CoCreateInstance: {81397204-f51a-4571-8d7b-dc030521aabd}
:WRAPPER:CoCreateInstance/RIID: {3050f429-98b5-11cf-bb82-00aa00bdc
:WRAPPER: INPROC SERVER C:\WINDOWS\system32\dxtrans.dll
:WRAPPER:LoadLibrary: C:\WINDOWS\system32\dxtrans.dll
:LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c80e4cd = GetModuleH
:LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c80ac6e = FreeLibrar
:LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c80ae30 = GetProcAdd
:LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c80aedb = LoadLibrar
:LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c801af5 = LoadLibrar
:LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c809bd7 = CloseHandl

[ 27784:07b0] :LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c801812 = ReadFile


[ 27784:07b0] :LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c810b07 = GetFileSiz
e
[ 27784:07b0] :LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c8107f0 = CreateFile
W
[ 27784:07b0] :LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c801d7b = LoadLibrar
yA
[ 27784:07b0] :LAUNCHER:WRAPPER: ATL.DLL -> KERNEL32.dll!0x7c8449fd = SetUnhandl
edExceptionFilter
[ 27784:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\dxtrans.dll -> KERNEL32.dll
!0x7c80ac6e = FreeLibrary
[ 27784:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\dxtrans.dll -> KERNEL32.dll
!0x7c80ae30 = GetProcAddress
[ 27784:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\dxtrans.dll -> KERNEL32.dll
!0x7c8449fd = SetUnhandledExceptionFilter
[ 27784:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\dxtrans.dll -> KERNEL32.dll
!0x7c809bd7 = CloseHandle
[ 27784:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\dxtrans.dll -> ole32.dll!0x
774d057e = CoCreateInstance
[ 27784:07b0] :LAUNCHER:WRAPPER: C:\WINDOWS\system32\dxtrans.dll -> OLEAUT32.dll
!0x770f9d5a = LoadRegTypeLib
[ 27784:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\dxtrans.dll, handle is 6
c2c0000
[ 27785:07b0] :WRAPPER:LoadLibrary: C:\WINDOWS\system32\dxtrans.dll, handle is 6
c2c0000
[ 27785:07b0] :DLL_LOADER: fixuping imports of C:\WINDOWS\system32\dxtrans.dll
[ 27786:07b0] :WRAPPER:CoCreateInstance: {d1fe6762-fc48-11d0-883a-3c8b00c10000}
[ 27786:07b0] :WRAPPER:CoCreateInstance/RIID: {6a950b2b-a971-11d1-81c8-0000f8755
7db}
[ 27786:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\dxtrans.dll
[ 27787:07b0] :WRAPPER:CoCreateInstance: {a7ee7f34-3bd1-427f-9231-f941e9b7e1fe}
[ 27787:07b0] :WRAPPER:CoCreateInstance/RIID: {22b07b33-8bfb-49d4-9b90-0938370c9
019}
[ 27787:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\dxtrans.dll
[ 27838:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 27838:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 27838:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 27838:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27838:07b0] :WRAPPER:FreeLibrary:77a50000, 'C:\WINDOWS\system32\CRYPT32.dll'
[ 27838:07b0] :WRAPPER:FreeLibrary:77fc0000, 'C:\WINDOWS\system32\Secur32.dll'
[ 27879:07b0] :WRAPPER:FreeLibrary:77bd0000, 'C:\WINDOWS\system32\VERSION.dll'
[ 27879:07b0] :WRAPPER:FreeLibrary:7e6a0000, 'C:\WINDOWS\system32\SHELL32.dll'
[ 27879:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 27879:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27879:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 27879:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27880:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 27880:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27881:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 27881:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27882:07b0] :WRAPPER:CoCreateInstance: {f414c260-6ac0-11cf-b6d1-00aa00bbbb58}
[ 27882:07b0] :WRAPPER:CoCreateInstance/RIID: {bb1a2ae1-a4f9-11cf-8f20-00805f2cd
064}
[ 27882:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\jscript.dll
[ 27882:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 27882:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27882:07b0] :WRAPPER:CoCreateInstance: {6c736db1-bd94-11d0-8a23-00aa00b58e10}
[ 27882:07b0] :WRAPPER:CoCreateInstance/RIID: {6c736dc1-ab0d-11d0-a2ad-00a0c90f2
7e8}
[ 27882:07b0] :WRAPPER:CoCreateInstance: {275c23e2-3747-11d0-9fea-00aa003f8646}

[ 27882:07b0] :WRAPPER:CoCreateInstance/RIID: {275c23e1-3747-11d0-9fea-00aa003f8


646}
[ 27882:07b0] :WRAPPER: INPROC SERVER C:\WINDOWS\system32\mlang.dll
[ 27899:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 27899:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 27948:07b0] :WRAPPER:FreeLibrary:7dbe0000, 'C:\WINDOWS\system32\mshtml.dll'
[ 77627:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78133:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78133:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78133:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 78133:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 78133:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78133:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78133:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78133:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78133:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 78133:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 78134:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78134:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78147:07b0] :WRAPPER:FreeLibrary:4eba0000, 'C:\WINDOWS\WinSxS\x86_Microsoft.Wi
ndows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GDIPlus.dll'
[ 78148:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78150:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78150:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78150:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 78150:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 78150:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78150:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78150:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78150:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78150:07b0] :WRAPPER:LoadLibrary: ntdll.dll, handle is 7c910000
[ 78150:07b0] :WRAPPER:FreeLibrary:7c910000, 'C:\WINDOWS\system32\ntdll.dll'
[ 78150:07b0] :WRAPPER:LoadLibrary: kernel32.dll, handle is 7c800000
[ 78150:07b0] :WRAPPER:FreeLibrary:7c800000, 'C:\WINDOWS\system32\kernel32.dll'
[ 78235:07b0] :WRAPPER:FreeLibrary:5b150000, 'C:\WINDOWS\system32\uxtheme.dll'
[ 78259:07b0] :WRAPPER:FreeLibrary:621f0000, 'C:\WINDOWS\system32\mciqtz32.dll'
[ 78260:07b0] :WRAPPER:FreeLibrary:10000000, 'C:\WINDOWS\system32\Macromed\Flash
\Flash32_11_2_202_228.ocx'
[ 78260:07b0] :WRAPPER:FreeLibrary:6c2c0000, 'C:\WINDOWS\system32\dxtrans.dll'
[ 78260:07b0] :WRAPPER:FreeLibrary:75d50000, 'C:\WINDOWS\system32\mshtmled.dll'
[ 78260:07b0] :WRAPPER:FreeLibrary:770f0000, 'C:\WINDOWS\system32\oleaut32.dll'
[ 78260:07b0] :WRAPPER:SetUnhandledExceptionFilter: 0x00000000
[ 78260:07b0] :BOXMAN:Remove temporary files and objects
[ 78260:07b0] :LAUNCHER:ExitProcess(0x00000000)
[ 78260:07b0] :LAUNCHER: exiting
[ 78261:07b0] :WRAPPER:FreeLibrary:0b010001, '???'
[ 78261:07b0] :WRAPPER:FreeLibrary:08650001, '???'
[ 78262:07b0] :WRAPPER:FreeLibrary:7e390000, 'C:\WINDOWS\system32\USER32.dll'
[ 78262:07b0] :WRAPPER:FreeLibrary:770f0000, 'C:\WINDOWS\system32\oleaut32.dll'
[ 78263:07b0] :WRAPPER:FreeLibrary:75dd0000, 'C:\WINDOWS\system32\mlang.dll'
[ 78263:07b0] :WRAPPER:FreeLibrary:76ea0000, 'C:\WINDOWS\system32\RASAPI32.DLL'
[ 78263:07b0] :WRAPPER:FreeLibrary:76e50000, 'C:\WINDOWS\system32\rasman.dll'
[ 78263:07b0] :WRAPPER:FreeLibrary:76e40000, 'C:\WINDOWS\system32\rtutils.dll'
[ 78264:07b0] :WRAPPER:FreeLibrary:5b150000, 'C:\WINDOWS\system32\uxtheme.dll'
[ 78264:07b0] :WRAPPER:FreeLibrary:70e20000, 'C:\WINDOWS\system32\asycfilt.dll'
[ 78265:07b0] :WRAPPER:SetUnhandledExceptionFilter: 0x004f7a36
[ 78265:07b0] :WRAPPER:FreeLibrary:00000000, 'C:\Documents and Settings\CABINA9\
Mis documentos\Downloads\trainer v4\trainer v4.exe'
[ 78265:07b0] :WRAPPER:FreeLibrary:77c40000, 'C:\WINDOWS\system32\msv1_0.dll'
[ 78265:07b0] :WRAPPER:FreeLibrary:767b0000, 'C:\WINDOWS\system32\schannel.dll'

[ 78266:07b0] :WRAPPER:FreeLibrary:00000000, 'C:\Documents


Mis documentos\Downloads\trainer v4\trainer v4.exe'
[ 78266:07b0] :WRAPPER:FreeLibrary:00000000, 'C:\Documents
Mis documentos\Downloads\trainer v4\trainer v4.exe'
[ 78266:07b0] :WRAPPER:FreeLibrary:00000000, 'C:\Documents
Mis documentos\Downloads\trainer v4\trainer v4.exe'
[ 78266:07b0] :WRAPPER:FreeLibrary:00000000, 'C:\Documents
Mis documentos\Downloads\trainer v4\trainer v4.exe'

and Settings\CABINA9\
and Settings\CABINA9\
and Settings\CABINA9\
and Settings\CABINA9\

Potrebbero piacerti anche